File: script-html-via-cross-origin-blob-url.sub.html

package info (click to toggle)
thunderbird 1%3A91.13.0-1~deb11u1
  • links: PTS, VCS
  • area: main
  • in suites: bullseye
  • size: 2,953,400 kB
  • sloc: cpp: 6,084,049; javascript: 4,790,441; ansic: 3,341,496; python: 862,958; asm: 366,542; xml: 204,277; java: 152,477; sh: 111,436; makefile: 21,388; perl: 15,312; yacc: 4,583; objc: 3,026; lex: 1,720; exp: 762; pascal: 635; awk: 564; sql: 453; php: 436; lisp: 432; ruby: 99; sed: 69; csh: 45
file content (38 lines) | stat: -rw-r--r-- 1,439 bytes parent folder | download | duplicates (29)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
<!DOCTYPE html>
<!-- Test verifies that cross-origin blob URIs are blocked both with and
  without CORB.
-->
<meta charset="utf-8">
<script src="/resources/testharness.js"></script>
<script src="/resources/testharnessreport.js"></script>
<div id=log></div>
<script>
async_test(function(t) {
  function step1_createSubframe() {
    addEventListener("message", function(e) {
      t.step(function() { step2_processSubframeMsg(e.data); })
    });
    var subframe = document.createElement("iframe")
    // www1 is cross-origin, to ensure that the received blob will be cross-origin.
    subframe.src = 'http://{{domains[www1]}}:{{ports[http][0]}}/fetch/corb/resources/subframe-that-posts-html-containing-blob-url-to-parent.html';
    document.body.appendChild(subframe);
  }

  function step2_processSubframeMsg(msg) {
    assert_false(msg.hasOwnProperty('error'), 'unexpected property found: "error"');
    assert_equals(msg.blob_type, 'text/html');
    assert_equals(msg.blob_size, 147);

    // With and without CORB loading of a cross-origin blob should be blocked
    // (this is verified by expecting |script.onerror|, but not |script.onload|
    // below).
    var script = document.createElement("script")
    script.src = msg.blob_url;
    script.onerror = t.step_func_done(function(){})
    script.onload = t.unreached_func("Unexpected load event")
    document.body.appendChild(script)
  }

  step1_createSubframe();
});
</script>