Source code
Revision control
Copy as Markdown
Other Tools
Test Info:
- This WPT test may be referenced by the following Test IDs:
- /trusted-types/navigate-to-javascript-url-009.html - WPT Dashboard Interop Dashboard
<!DOCTYPE html>
<meta http-equiv="Content-Security-Policy"
content="require-trusted-types-for 'script'">
<script src="/resources/testharness.js"></script>
<script src="/resources/testharnessreport.js"></script>
<script>
// A javascript: URL in the src attribute of a freshly inserted iframe is
// navigated to with initialInsertion set to true, which is the one case where
// "navigate to a javascript: URL" runs the iframe load event steps when no
// Document is produced. The default policy runs author code in the middle of
// that algorithm, so it can remove the iframe first, leaving the navigable
// without a container to fire the load event at.
//
// navigate-to-javascript-url-007-crash.html covers the same re-entrancy for a
// window.location navigation, where initialInsertion is false and this branch
// is not reached.
promise_test(async _ => {
let javaScriptExecuted = false;
window.executeJavaScript = _ => { javaScriptExecuted = true; };
let loadEvents = 0;
const iframe = document.createElement("iframe");
iframe.addEventListener("load", _ => { loadEvents++; });
iframe.src = "javascript:parent.executeJavaScript()";
document.head.appendChild(iframe);
// The policy container of the synthetic request is snapshotted from the
// document that inserted the iframe, but the iframe's initial about:blank
// document inherits the same CSP, so install the default policy on both to
// keep the test independent of which global the pre-navigation check
const removeIframe = { createScript: s => { iframe.remove(); return s; } };
trustedTypes.createPolicy("default", removeIframe);
iframe.contentWindow.trustedTypes.createPolicy("default", removeIframe);
// Wait for the queued navigation task to have run.
if (window.requestIdleCallback) {
await new Promise(resolve => requestIdleCallback(resolve));
} else {
await new Promise(resolve => requestAnimationFrame(_ => requestAnimationFrame(resolve)));
}
assert_false(javaScriptExecuted, "JavaScript shouldn't have been executed");
assert_equals(loadEvents, 0, "No load event should be fired at the removed iframe");
}, "Removing an iframe from the default policy during the pre-navigation check of its javascript: URL src should not fire a load event at it.");
</script>