summaryrefslogtreecommitdiffstats
path: root/testing/web-platform/tests/feature-policy/feature-policy-frame-policy-allowed-for-some.https.sub.html
blob: 5dfd8430d2f5772c0d5b3149fc0b1dbfcd0c96f6 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
<!DOCTYPE html>
<html>
<head>
  <meta name="timeout" content="long">
  <script src=/resources/testharness.js></script>
  <script src=/resources/testharnessreport.js></script>
</head>
<body>
  <script src=/feature-policy/resources/featurepolicy.js></script>
  <!-- Feature-Policy: fullscreen 'self' cross_origin https://www.example.com; -->
  <script>
  'use strict';
  var same_origin = 'https://{{domains[]}}:{{ports[https][0]}}';
  var cross_origin = 'https://{{domains[www]}}:{{ports[https][0]}}';
  var cross_origin1 = 'https://{{domains[www1]}}:{{ports[https][0]}}';
  var same_origin_src = '/feature-policy/resources/feature-policy-allowedfeatures.html';
  var cross_origin_src = cross_origin + same_origin_src;
  var cross_origin_src1 = cross_origin1 + same_origin_src;
  var data_src = 'data:text/html,<h1>data: URL</h1>';
  // Test feature policy with same_origin_src and cross_origin_src.
  var policies = [
    {allow: "*", sameOriginTestExpect: true, crossOriginTestExpect: true, crossOrigin1TestExpect: false, dataOriginTestExpect: false},
    {allow: "'self'", sameOriginTestExpect: true, crossOriginTestExpect: false, crossOrigin1TestExpect: false, dataOriginTestExpect: false},
    {allow: "'none'", sameOriginTestExpect: false, crossOriginTestExpect: false, crossOrigin1TestExpect: false, dataOriginTestExpect: false},
    {allow: "'self' " + cross_origin + " https://www.example.com", sameOriginTestExpect: true, crossOriginTestExpect: true, crossOrigin1TestExpect: false, dataOriginTestExpect: false}];
  var pipe_front = '?pipe=sub|header(Feature-Policy,fullscreen ';
  var pipe_end = ';)';
  var header_policies = ["*", "'self'", "'none'"];

  // Test that frame.policy inherits from parent's header policy when allow
  // attribute is not specified.
  test(function() {
    test_frame_policy('fullscreen', same_origin_src, undefined, true);
  }, 'Test frame policy on same origin iframe inherit from header policy.');
  test(function() {
    test_frame_policy('fullscreen', cross_origin_src, undefined, false);
  }, 'Test frame policy on cross origin iframe inherit from header policy.');
  test(function() {
    test_frame_policy('fullscreen', cross_origin_src1, undefined, false);
  }, 'Test frame policy on another cross origin iframe inherit from header policy.');
  test(function() {
    test_frame_policy('fullscreen', undefined, true, true);
  }, 'Test frame policy on srcdoc iframe inherit from header policy.');
  test(function() {
    test_frame_policy('fullscreen', same_origin_src, true, true);
  }, 'Test frame policy on srcdoc + same origin iframe inherit from header policy.');
  test(function() {
    test_frame_policy('fullscreen', cross_origin_src, true, true);
  }, 'Test frame policy on srcdoc + cross origin iframe inherit from header policy.');
  test(function() {
    test_frame_policy('fullscreen', cross_origin_src1, true, true);
  }, 'Test frame policy on srcdoc + another cross origin iframe inherit from header policy.');
  test(function() {
    test_frame_policy('fullscreen', data_src, undefined, false);
  }, 'Test frame policy on data: URL cross origin iframe inherit from header policy.');

  // Test frame policy with allow attribute set to be one of the policies above.
  for (var i = 0; i < policies.length; i++) {
    test(function() {
      test_frame_policy(
        'fullscreen', same_origin_src, undefined,
        policies[i].sameOriginTestExpect,
        'fullscreen ' + policies[i].allow + ';');
    }, 'Test frame policy on same origin iframe with allow = "' + policies[i].allow + '".');
    test(function() {
      test_frame_policy(
        'fullscreen', cross_origin_src, undefined,
        policies[i].crossOriginTestExpect,
        'fullscreen ' + policies[i].allow + ';');
    }, 'Test frame policy on cross origin iframe with allow = "' + policies[i].allow + '".');
    test(function() {
      test_frame_policy(
        'fullscreen', cross_origin_src1, undefined,
        policies[i].crossOrigin1TestExpect,
        'fullscreen ' + policies[i].allow + ';');
    }, 'Test frame policy on another cross origin iframe with allow = "' + policies[i].allow + '".');
    test(function() {
      test_frame_policy(
        'fullscreen', undefined, true, policies[i].sameOriginTestExpect,
        'fullscreen ' + policies[i].allow + ';');
    }, 'Test frame policy on srcdoc iframe with allow = "' + policies[i].allow + '".');
    test(function() {
      test_frame_policy(
        'fullscreen', same_origin_src, true, policies[i].sameOriginTestExpect,
        'fullscreen ' + policies[i].allow + ';');
    }, 'Test frame policy on srcdoc + same origin iframe with allow = "' + policies[i].allow + '".');
    test(function() {
      test_frame_policy(
        'fullscreen', cross_origin_src, true, policies[i].sameOriginTestExpect,
        'fullscreen ' + policies[i].allow + ';');
    }, 'Test frame policy on srcdoc + cross origin iframe with allow = "' + policies[i].allow + '".');
    test(function() {
      test_frame_policy(
        'fullscreen', cross_origin_src1, true, policies[i].sameOriginTestExpect,
        'fullscreen ' + policies[i].allow + ';');
    }, 'Test frame policy on srcdoc + another cross origin iframe with allow = "' + policies[i].allow + '".');
    test(function() {
      test_frame_policy(
        'fullscreen', data_src, undefined, policies[i].dataOriginTestExpect,
        'fullscreen ' + policies[i].allow + ';');
    }, 'Test frame policy on data: URL cross origin iframe with allow = "' + policies[i].allow + '".');
  }

  // Test that the header policy of the iframe document does not change the
  // frame policy.
  for (var i = 0; i < policies.length; i++) {
    for (var j = 0; j < header_policies.length; j++) {
      test(function() {
        test_frame_policy(
          'fullscreen',
          same_origin_src + pipe_front + header_policies[j] + pipe_end,
          undefined, policies[i].sameOriginTestExpect,
          'fullscreen ' + policies[i].allow + ';');
      }, 'Test frame policy on same origin iframe with allow = "' + policies[i].allow +
         '" and header policy = "Feature-Policy: fullscreen ' + header_policies[j] + ';".');
      test(function() {
        test_frame_policy(
          'fullscreen',
          cross_origin_src + pipe_front + header_policies[j] + pipe_end,
          undefined, policies[i].crossOriginTestExpect,
          'fullscreen ' + policies[i].allow + ';');
      }, 'Test frame policy on cross origin iframe with allow = "' + policies[i].allow +
         '" and header policy = "Feature-Policy: fullscreen ' + header_policies[j] + ';".');
      test(function() {
        test_frame_policy(
          'fullscreen',
          cross_origin_src1 + pipe_front + header_policies[j] + pipe_end,
          undefined, policies[i].crossOrigin1TestExpect,
          'fullscreen ' + policies[i].allow + ';');
      }, 'Test frame policy on another cross origin iframe with allow = "' + policies[i].allow +
         '" and header policy = "Feature-Policy: fullscreen ' + header_policies[j] + ';".');
    }
  }
  </script>
</body>
</html>