Source code
Revision control
Copy as Markdown
Other Tools
Test Info:
- This WPT test may be referenced by the following Test IDs:
- /web-bundle/subresource-loading/csp-allowed.https.tentative.html - WPT Dashboard Interop Dashboard
<!DOCTYPE html>
<title>CSP for subresource WebBundle (allowed cases)</title>
<link
rel="help"
/>
<meta
http-equiv="Content-Security-Policy"
content="
script-src
'unsafe-inline';
img-src
/>
<script src="/resources/testharness.js"></script>
<script src="/resources/testharnessreport.js"></script>
<body>
<script type="webbundle">
{
"source": "../resources/wbn/subresource.wbn",
}
</script>
<script type="webbundle">
{
"source": "../resources/wbn/uuid-in-package.wbn",
"resources": ["uuid-in-package:020111b3-437a-4c5c-ae07-adb6bbffb720"
]
}
</script>
<script>
promise_test(() => {
return new Promise((resolve, reject) => {
const img = document.createElement("img");
img.src =
img.onload = resolve;
img.onerror = reject;
document.body.appendChild(img);
});
}, "URL matching of CSP should be done based on the subresource URL " +
"when the subresource URL is HTTPS URL.");
promise_test(async () => {
const result = await new Promise((resolve) => {
// This function will be called from the script.
window.report_result = resolve;
const script = document.createElement("script");
script.src = "uuid-in-package:020111b3-437a-4c5c-ae07-adb6bbffb720";
document.body.appendChild(script);
});
assert_equals(result, "OK");
}, "URL matching of script-src CSP should be done based on the bundle URL " +
"when the subresource URL is uuid-in-package: URL.");
</script>
</body>