File: navigate-cross-origin-iframe-to-same-url-with-fragment-fire-load-event.html

package info (click to toggle)
thunderbird 1%3A144.0.1-1
  • links: PTS, VCS
  • area: main
  • in suites: experimental
  • size: 4,725,312 kB
  • sloc: cpp: 7,869,225; javascript: 5,974,276; ansic: 3,946,747; python: 1,421,062; xml: 654,642; asm: 474,045; java: 183,117; sh: 110,973; makefile: 20,398; perl: 14,362; objc: 13,086; yacc: 4,583; pascal: 3,448; lex: 1,720; ruby: 999; exp: 762; sql: 731; awk: 580; php: 436; lisp: 430; sed: 69; csh: 10
file content (31 lines) | stat: -rw-r--r-- 1,067 bytes parent folder | download | duplicates (20)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
<!doctype html>
<script src="/resources/testharness.js"></script>
<script src="/resources/testharnessreport.js"></script>
<script src="/common/get-host-info.sub.js"></script>
<body>
<script>
async_test(t => {
  const crossOriginUrl = new URL(get_host_info().HTTPS_REMOTE_ORIGIN);
  crossOriginUrl.pathname = "/common/blank.html";
  const i = document.createElement("iframe");
  i.src = crossOriginUrl;
  document.body.appendChild(i);

  let wasLoadEventFired = false;
  i.onload = t.step_func(() => {
    // Though iframe is cross-origin and changing hash leads soft reload, the
    // load event should be fired to protect sensitive information.
    // See: https://crbug.com/1248444
    crossOriginUrl.hash = "#foo";
    i.onload = () => {
      assert_false(wasLoadEventFired)
      wasLoadEventFired = true;
      // Wait for a while to ensure other onload events are never fired.
      t.step_timeout(() => t.done(), 100);
    };
    i.src = crossOriginUrl;
  });

}, "Changing the URL hash of a cross-origin iframe should fire a load event");
</script>
</body>