File: script-html-via-cross-origin-blob-url.sub.html

package info (click to toggle)
thunderbird 1%3A68.10.0-1~deb9u1
  • links: PTS, VCS
  • area: main
  • in suites: stretch
  • size: 2,754,812 kB
  • sloc: cpp: 5,411,679; javascript: 4,161,772; ansic: 2,639,702; python: 763,064; java: 346,606; xml: 266,623; asm: 265,884; sh: 117,270; lisp: 41,340; makefile: 23,560; perl: 18,042; objc: 5,277; yacc: 1,778; ada: 1,681; pascal: 1,673; lex: 1,417; cs: 879; exp: 527; awk: 495; php: 436; ruby: 221; sed: 69; csh: 27
file content (38 lines) | stat: -rw-r--r-- 1,439 bytes parent folder | download | duplicates (29)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
<!DOCTYPE html>
<!-- Test verifies that cross-origin blob URIs are blocked both with and
  without CORB.
-->
<meta charset="utf-8">
<script src="/resources/testharness.js"></script>
<script src="/resources/testharnessreport.js"></script>
<div id=log></div>
<script>
async_test(function(t) {
  function step1_createSubframe() {
    addEventListener("message", function(e) {
      t.step(function() { step2_processSubframeMsg(e.data); })
    });
    var subframe = document.createElement("iframe")
    // www1 is cross-origin, to ensure that the received blob will be cross-origin.
    subframe.src = 'http://{{domains[www1]}}:{{ports[http][0]}}/fetch/corb/resources/subframe-that-posts-html-containing-blob-url-to-parent.html';
    document.body.appendChild(subframe);
  }

  function step2_processSubframeMsg(msg) {
    assert_false(msg.hasOwnProperty('error'), 'unexpected property found: "error"');
    assert_equals(msg.blob_type, 'text/html');
    assert_equals(msg.blob_size, 147);

    // With and without CORB loading of a cross-origin blob should be blocked
    // (this is verified by expecting |script.onerror|, but not |script.onload|
    // below).
    var script = document.createElement("script")
    script.src = msg.blob_url;
    script.onerror = t.step_func_done(function(){})
    script.onload = t.unreached_func("Unexpected load event")
    document.body.appendChild(script)
  }

  step1_createSubframe();
});
</script>