File: navigate-cross-origin-iframe-to-same-url-with-fragment-fire-load-event.html

package info (click to toggle)
thunderbird 1%3A128.14.0esr-1~deb12u1
  • links: PTS, VCS
  • area: main
  • in suites: bookworm
  • size: 4,334,824 kB
  • sloc: cpp: 7,391,917; javascript: 5,617,271; ansic: 3,833,216; python: 1,230,742; xml: 619,690; asm: 456,022; java: 179,892; sh: 118,796; makefile: 21,908; perl: 14,825; objc: 12,399; yacc: 4,583; pascal: 2,973; lex: 1,720; ruby: 1,190; exp: 762; sql: 674; awk: 580; php: 436; lisp: 430; sed: 70; csh: 10
file content (31 lines) | stat: -rw-r--r-- 1,067 bytes parent folder | download | duplicates (18)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
<!doctype html>
<script src="/resources/testharness.js"></script>
<script src="/resources/testharnessreport.js"></script>
<script src="/common/get-host-info.sub.js"></script>
<body>
<script>
async_test(t => {
  const crossOriginUrl = new URL(get_host_info().HTTPS_REMOTE_ORIGIN);
  crossOriginUrl.pathname = "/common/blank.html";
  const i = document.createElement("iframe");
  i.src = crossOriginUrl;
  document.body.appendChild(i);

  let wasLoadEventFired = false;
  i.onload = t.step_func(() => {
    // Though iframe is cross-origin and changing hash leads soft reload, the
    // load event should be fired to protect sensitive information.
    // See: https://crbug.com/1248444
    crossOriginUrl.hash = "#foo";
    i.onload = () => {
      assert_false(wasLoadEventFired)
      wasLoadEventFired = true;
      // Wait for a while to ensure other onload events are never fired.
      t.step_timeout(() => t.done(), 100);
    };
    i.src = crossOriginUrl;
  });

}, "Changing the URL hash of a cross-origin iframe should fire a load event");
</script>
</body>