Source code

Revision control

Copy as Markdown

Other Tools

Test Info:

<!DOCTYPE html>
<html>
<head>
<title>Cross origin iframes have their URI censored</title>
<script src="/resources/testharness.js"></script>
<script src="/resources/testharnessreport.js"></script>
<!-- CSP headers
Content-Security-Policy: script-src 'self' 'unsafe-inline'
Content-Security-Policy-Report-Only: frame-src 'none'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID=$id
-->
</head>
<body>
<script>
let iframe = document.createElement('iframe');
"/content-security-policy/support/postmessage-pass.html";
let test_load_event = async_test("The load event triggers");
iframe.onload = test_load_event.step_func_done();
let test_iframe_allowed = async_test("The iframe is allowed to load.");
window.addEventListener("message", test_iframe_allowed.step_func(event => {
if (event.source === iframe.contentWindow) {
assert_equals(event.data, "PASS");
test_iframe_allowed.done();
}
}));
let test_spv = async_test("The securitypolicyviolation is triggered.");
window.addEventListener("securitypolicyviolation",
test_spv.step_func_done(e => {
assert_equals(e.blockedURI,
}));
document.body.appendChild(iframe);
</script>
<!-- Ensure that we get the censored URI (without the full path) here: -->
<script async defer src='../support/checkReport.sub.js?reportField=blocked-uri&reportValue=http://{{domains[www1]}}:{{ports[http][0]}}'></script>
</body>
</html>