Source code
Revision control
Copy as Markdown
Other Tools
Test Info:
- This WPT test may be referenced by the following Test IDs:
- /content-security-policy/securitypolicyviolation/targeting-for-inline-handler-in-markup.html - WPT Dashboard Interop Dashboard
<!doctype html>
<meta http-equiv="Content-Security-Policy" content="script-src 'nonce-abc'; style-src 'self'">
<script nonce="abc" src="/resources/testharness.js"></script>
<script nonce="abc" src="/resources/testharnessreport.js"></script>
<script nonce="abc">
var violation_dispatched = false;
var document_watcher;
promise_test(async t => {
document_watcher = new EventWatcher(t, document, ["securitypolicyviolation"])
.wait_for("securitypolicyviolation").then(t.step_func(e => {
violation_dispatched = true;
assert_equals(e.blockedURI, "inline");
assert_equals(e.lineNumber, 0);
assert_in_array(e.columnNumber, [0, 1]);
assert_equals(e.target, document.getElementById('target'));
}));
return document_watcher;
});
</script>
<a id="target" onclick="void(0)">Click me</a>
<script nonce="abc">
promise_test(async t => {
var a = document.getElementById('target');
const timeout_promise = () => new Promise((_, reject) => t.step_timeout(
() => reject(new Error('Timed out waiting for securitypolicyviolation')), 1000));
const get_failed_watchers = (results) => results.flatMap(
(r, i) => r.status !== "fulfilled" ? [ `#${i}: ${r.reason}` ] : []);
var watchers = [ Promise.race([document_watcher, timeout_promise()]) ];
if (!violation_dispatched) {
watchers.push(Promise.race([new EventWatcher(t, a, ["securitypolicyviolation"])
.wait_for("securitypolicyviolation").then(t.step_func(e => {
assert_equals(e.blockedURI, "inline");
assert_equals(e.lineNumber, 0);
assert_in_array(e.columnNumber, [0, 1]);
assert_equals(e.target, a);
})),
timeout_promise()]));
}
await Promise.allSettled(watchers).then(results => {
assert_array_equals(get_failed_watchers(results), []);
});
});
</script>