summaryrefslogtreecommitdiffstats
path: root/testing/web-platform/tests/cookies/samesite-none-secure/cookies-without-samesite-must-be-secure.https.html
blob: 18cf0516e64ec2c416b013b232d4247b5647b22c (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
<!DOCTYPE html>
<meta charset="utf-8">
<meta name="timeout" content="long">
<script src="/resources/testharness.js"></script>
<script src="/resources/testharnessreport.js"></script>
<script src="/cookies/resources/cookie-helper.sub.js"></script>
<script>
promise_test(t => {
  var value = "" + Math.random();
  return resetSameSiteNoneCookies(SECURE_ORIGIN, value)
    .then(_ => {
      return credFetch(SECURE_ORIGIN + "/cookies/resources/list.py")
        .then(r => r.json())
        .then(cookies => {
          assert_not_equals(cookies["samesite_none_insecure"], value, "Non-Secure SameSite=None cookie is rejected.");
          assert_equals(cookies["samesite_none_secure"], value, "Secure SameSite=None cookie is set.");
        })
    });
}, "SameSite=None cookies are rejected unless the Secure attribute is set.");
</script>