File: sandbox-window-open-srcdoc.html

package info (click to toggle)
thunderbird 1%3A128.14.0esr-1~deb12u1
  • links: PTS, VCS
  • area: main
  • in suites: bookworm
  • size: 4,334,824 kB
  • sloc: cpp: 7,391,917; javascript: 5,617,271; ansic: 3,833,216; python: 1,230,742; xml: 619,690; asm: 456,022; java: 179,892; sh: 118,796; makefile: 21,908; perl: 14,825; objc: 12,399; yacc: 4,583; pascal: 2,973; lex: 1,720; ruby: 1,190; exp: 762; sql: 674; awk: 580; php: 436; lisp: 430; sed: 70; csh: 10
file content (52 lines) | stat: -rw-r--r-- 1,765 bytes parent folder | download | duplicates (22)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
<!DOCTYPE html>
<meta charset=utf-8>
<title>window.open("about:srcdoc") from a sandboxed iframe</title>
<script src="/resources/testharness.js"></script>
<script src="/resources/testharnessreport.js"></script>
<body>
<script>
// Check what happens when executing window.open("about:srcdoc") from a
// sandboxed iframe. Srcdoc can't be loaded in the main frame. It should
// result in an error page. The error page should be cross-origin with the
// opener.
//
// This test covers an interesting edge case. A main frame should inherit
// sandbox flags. However the document loaded is an internal error page. This
// might trigger some assertions, especially if the implementation wrongly
// applies the sandbox flags of the opener to the internal error page document.
//
// This test is mainly a coverage test. It passes if it doesn't crash.
async_test(test => {
  let iframe = document.createElement("iframe");
  iframe.sandbox = "allow-scripts allow-popups allow-same-origin";
  iframe.srcdoc = `
    <script>
      let w = window.open();
      onunload = () => w.close();

      let notify = () => {
        try {
          w.origin; // Will fail after navigating to about:srcdoc.
          parent.postMessage("pending", "*");
        } catch (e) {
          parent.postMessage("done", "*");
        };
      };

      addEventListener("message", notify);
      notify();

      w.location = "about:srcdoc"; // Error page.
    </scr`+`ipt>
  `;

  let closed = false;
  addEventListener("message", event => {
    closed = (event.data === "done");
    iframe.contentWindow.postMessage("ping","*");
  });

  document.body.appendChild(iframe);
  test.step_wait_func_done(()=>closed);
}, "window.open('about:srcdoc') from sandboxed srcdoc doesn't crash.");
</script>