summaryrefslogtreecommitdiffstats
path: root/testing/web-platform/tests/background-fetch/content-security-policy.https.window.js
blob: 0b12185c5b37101c5cff68087df995fcf44caf71 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
// META: script=/service-workers/service-worker/resources/test-helpers.sub.js
// META: script=resources/utils.js
'use strict';

// Tests that requests blocked by Content Security Policy are rejected.
// https://w3c.github.io/webappsec-csp/#should-block-request

// This is not a comprehensive test of Content Security Policy - it is just
// intended to check that CSP checks are enabled.

var meta = document.createElement('meta');
meta.setAttribute('http-equiv', 'Content-Security-Policy');
meta.setAttribute('content', "connect-src 'none'");
document.head.appendChild(meta);

backgroundFetchTest(async (t, bgFetch) => {
  const fetch = await bgFetch.fetch(uniqueId(), '/');

  const record = await fetch.match('/');
  return promise_rejects_js(
      t, TypeError,
      record.responseReady);
}, 'fetch blocked by CSP should reject');