File: access-control-sandboxed-iframe-allow.htm

package info (click to toggle)
firefox-esr 78.15.0esr-1~deb10u1
  • links: PTS, VCS
  • area: main
  • in suites: buster
  • size: 3,301,296 kB
  • sloc: cpp: 5,665,905; javascript: 4,798,386; ansic: 2,878,233; python: 977,004; asm: 270,347; xml: 181,456; java: 111,756; sh: 72,926; makefile: 21,819; perl: 13,380; cs: 4,725; yacc: 4,565; objc: 3,026; pascal: 1,787; lex: 1,720; ada: 1,681; exp: 505; php: 436; lisp: 260; awk: 152; ruby: 103; csh: 80; sed: 53; sql: 45
file content (32 lines) | stat: -rw-r--r-- 1,153 bytes parent folder | download | duplicates (31)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
<!DOCTYPE html>
<html>
  <head>
    <title>Tests that sandboxed iframe has CORS XHR access to a server that accepts all domains</title>
    <script src="/resources/testharness.js"></script>
    <script src="/resources/testharnessreport.js"></script>
    <script src="/common/get-host-info.sub.js"></script>
  </head>
  <body>
    <script type="text/javascript">
async_test((test) => {
  window.addEventListener("message", test.step_func((evt) => {
    if (evt.data === "ready") {
      document.getElementById("frame").contentWindow.postMessage(
          get_host_info().HTTP_ORIGIN +
          "/xhr/resources/pass.txt?pipe=" +
          "header(Cache-Control,no-store)|" +
          "header(Content-Type,text/plain)|" +
          "header(Access-Control-Allow-Credentials,true)|" +
          "header(Access-Control-Allow-External,true)|" +
          "header(Access-Control-Allow-Origin,*)", "*");
    } else {
      assert_equals(evt.data.trim(), "PASS");
      test.done();
    }
  }), false);
});
    </script>
    <iframe id="frame" sandbox="allow-scripts" src="/xhr/resources/access-control-sandboxed-iframe.html">
    </iframe>
  </body>
</html>