File: sandbox-disallow-popups.html

package info (click to toggle)
thunderbird 1%3A91.13.0-1~deb11u1
  • links: PTS, VCS
  • area: main
  • in suites: bullseye
  • size: 2,953,400 kB
  • sloc: cpp: 6,084,049; javascript: 4,790,441; ansic: 3,341,496; python: 862,958; asm: 366,542; xml: 204,277; java: 152,477; sh: 111,436; makefile: 21,388; perl: 15,312; yacc: 4,583; objc: 3,026; lex: 1,720; exp: 762; pascal: 635; awk: 564; sql: 453; php: 436; lisp: 432; ruby: 99; sed: 69; csh: 45
file content (39 lines) | stat: -rw-r--r-- 1,161 bytes parent folder | download | duplicates (22)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
<!DOCTYPE html>
<meta charset=utf-8>
<title>window.open in sandbox iframe</title>
<script src="/resources/testharness.js"></script>
<script src="/resources/testharnessreport.js"></script>
<script src="/common/utils.js"></script>
<body>
<script>
setup({single_test: true});
// check that the popup's URL is not loaded
const uuid = token();
async function assert_popup_not_loaded() {
  const response = await fetch(`/fetch/api/resources/stash-take.py?key=${uuid}`);
  assert_equals(await response.json(), null); // is "loaded" if it loads
}

// check for message from the iframe
window.onmessage = e => {
  assert_equals(e.data, 'null', 'return value of window.open (stringified)');
  step_timeout(async () => {
    await assert_popup_not_loaded();
    done();
  }, 1000);
};
const iframe = document.createElement('iframe');
iframe.sandbox = 'allow-scripts';
iframe.srcdoc = `
  <script>
    let result;
    try {
      result = window.open('/fetch/api/resources/stash-put.py?key=${uuid}&value=loaded', '_blank');
    } catch(ex) {
      result = ex;
    }
    parent.postMessage(String(result), '*');
  <\/script>
`;
document.body.appendChild(iframe);
</script>