File: sandboxed-iframe.html

package info (click to toggle)
firefox-esr 78.15.0esr-1~deb11u1
  • links: PTS, VCS
  • area: main
  • in suites: bullseye
  • size: 3,301,156 kB
  • sloc: cpp: 5,665,905; javascript: 4,798,386; ansic: 2,878,233; python: 977,004; asm: 270,347; xml: 181,456; java: 111,756; sh: 72,926; makefile: 21,819; perl: 13,380; cs: 4,725; yacc: 4,565; objc: 3,026; pascal: 1,787; lex: 1,720; ada: 1,681; exp: 505; php: 436; lisp: 260; awk: 152; ruby: 103; csh: 80; sed: 53; sql: 45
file content (34 lines) | stat: -rw-r--r-- 720 bytes parent folder | download | duplicates (31)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
<!doctype html>
<html>
<script>
async function no_cors_should_be_rejected() {
  let thrown = false;
  try {
    const resp = await fetch('top.txt');
  } catch (e) {
    thrown = true;
  }
  if (!thrown) {
    throw Error('fetching "top.txt" should be rejected.');
  }
}

async function null_origin_should_be_accepted() {
  const url = 'top.txt?pipe=header(access-control-allow-origin,null)|' +
              'header(cache-control,no-store)';
  const resp = await fetch(url);
}

async function test() {
  try {
    await no_cors_should_be_rejected();
    await null_origin_should_be_accepted();
    parent.postMessage('PASS', '*');
  } catch (e) {
    parent.postMessage(e.message, '*');
  }
}

test();
</script>
</html>