summaryrefslogtreecommitdiffstats
path: root/testing/web-platform/tests/credential-management/otpcredential-iframe.https.html
blob: da3e572b6b5771fcc55f5bf828a1a0a0a6606fa3 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
<!doctype html>
<script src="/resources/testharness.js"></script>
<script src="/resources/testharnessreport.js"></script>
<script src="/common/get-host-info.sub.js"></script>
<div id=log>
<script>
'use strict';

const host = get_host_info();
const remoteBaseURL =
    host.HTTPS_REMOTE_ORIGIN +
    window.location.pathname.replace(/\/[^\/]*$/, '/');
const localBaseURL =
    host.HTTPS_ORIGIN +
    window.location.pathname.replace(/\/[^\/]*$/, '/');

promise_test(async t => {
  const messageWatcher = new EventWatcher(t, window, "message");
  var iframe = document.createElement("iframe");
  iframe.src = localBaseURL + "support/otpcredential-iframe.html";

  document.body.appendChild(iframe);

  const message = await messageWatcher.wait_for("message");
  assert_equals(message.data.result, "Pass");
  assert_equals(message.data.code, "ABC123");

}, "Test OTPCredential enabled in same origin iframes");

promise_test(async t => {
  const messageWatcher = new EventWatcher(t, window, "message");
  var iframe = document.createElement("iframe");
  iframe.src = remoteBaseURL + "support/otpcredential-iframe.html"
  iframe.allow = "otp-credentials";
  document.body.appendChild(iframe);

  const message = await messageWatcher.wait_for("message");
  assert_equals(message.data.result, "Pass");
  assert_equals(message.data.code, "ABC123");

}, "OTPCredential enabled in cross origin iframes with permissions policy");

promise_test(async t => {
  const messageWatcher = new EventWatcher(t, window, "message");
  var iframe = document.createElement("iframe");
  iframe.src = remoteBaseURL + "support/otpcredential-iframe.html"
  document.body.appendChild(iframe);

  const message = await messageWatcher.wait_for("message");
  assert_equals(message.data.result, "Fail");
  assert_equals(message.data.errorType, "NotAllowedError");

}, "OTPCredential disabled in cross origin iframes without permissions policy");
</script>