summaryrefslogtreecommitdiffstats
path: root/testing/web-platform/tests/content-security-policy/style-src/import-style-allowed.sub.html
blob: 02a2b2eecee8f997c8b82ea9195eae863508b33f (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
<!DOCTYPE html>
<html>
  <head>
    <title>import-style-allowed</title>
    <meta
      http-equiv="Content-Security-Policy"
      content="style-src 'unsafe-inline' 'self'; script-src http://{{host}}:{{ports[http][0]}}/resources/testharness.js http://{{host}}:{{ports[http][0]}}/resources/testharnessreport.js 'unsafe-inline' 'unsafe-inline'; connect-src 'self';"
    />
    <script src="/resources/testharness.js"></script>
    <script src="/resources/testharnessreport.js"></script>
  </head>

  <body>
    <script>
      promise_test(t => new Promise((resolve, reject) => {
        window.addEventListener("securitypolicyviolation", (err) => {
          if (err.blockedURI.endsWith("/resources/allowed.css")) {
            reject("Should not raise securitypolicyviolation.");
          }
        });
        import("./resources/allowed.css", { with: { type: "css" } }).then(resolve, reject)
      }), "import should be allowed");
    </script>
  </body>
</html>