File: sandbox-inherited-from-initiator-response.html

package info (click to toggle)
thunderbird 1%3A128.14.0esr-1~deb12u1
  • links: PTS, VCS
  • area: main
  • in suites: bookworm
  • size: 4,334,824 kB
  • sloc: cpp: 7,391,917; javascript: 5,617,271; ansic: 3,833,216; python: 1,230,742; xml: 619,690; asm: 456,022; java: 179,892; sh: 118,796; makefile: 21,908; perl: 14,825; objc: 12,399; yacc: 4,583; pascal: 2,973; lex: 1,720; ruby: 1,190; exp: 762; sql: 674; awk: 580; php: 436; lisp: 430; sed: 70; csh: 10
file content (46 lines) | stat: -rw-r--r-- 1,629 bytes parent folder | download | duplicates (22)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
<!DOCTYPE html>
<meta charset=utf-8>
<title>Inherit sandbox flags from the initiator's response</title>
<script src="/resources/testharness.js"></script>
<script src="/resources/testharnessreport.js"></script>
<body>
<script>
// Check sandbox flags are properly inherited when a document initiate a
// navigation inside another frame that it doesn't own directly.

// This check the sandbox flags defined by the response (e.g. CSP sandbox). See
// also the other test about sandbox flags inherited from the frame.
// => sandbox-inherited-from-initiators-frame.html

// Return a promise, resolving when |element| triggers |event_name| event.
let future = (element, event_name) => {
  return new Promise(resolve => {
    element.addEventListener(event_name, event => resolve(event))
  });
};

promise_test(async test => {
  const iframe_1 = document.createElement("iframe");
  const iframe_2 = document.createElement("iframe");

  iframe_1.id = "iframe_1";
  iframe_2.id = "iframe_2";

  iframe_2.src =
    "./resources/sandbox-inherited-from-initiator-response-helper.html";

  // Insert |iframe_1|. It will load the initial empty document, with no sandbox
  // flags.
  const iframe_1_load_1 = future(iframe_1, "load");
  document.body.appendChild(iframe_1);
  await iframe_1_load_1;

  // Insert |iframe_2|. It will load with sandbox flags. It will make |iframe_1|
  // to navigate toward a data-url, which should inherit the sandbox flags.
  const iframe_1_reply = future(window, "message");
  document.body.appendChild(iframe_2);
  const result = await iframe_1_reply;

  assert_equals("sandboxed", result.data);
})
</script>