diff options
Diffstat (limited to 'testing/web-platform/tests/content-security-policy/frame-src/frame-src-same-document.sub.html')
-rw-r--r-- | testing/web-platform/tests/content-security-policy/frame-src/frame-src-same-document.sub.html | 22 |
1 files changed, 22 insertions, 0 deletions
diff --git a/testing/web-platform/tests/content-security-policy/frame-src/frame-src-same-document.sub.html b/testing/web-platform/tests/content-security-policy/frame-src/frame-src-same-document.sub.html new file mode 100644 index 0000000000..9868f92955 --- /dev/null +++ b/testing/web-platform/tests/content-security-policy/frame-src/frame-src-same-document.sub.html @@ -0,0 +1,22 @@ +<script src="/resources/testharness.js"></script> +<script src="/resources/testharnessreport.js"></script> +<html> +<body></body> +<script> + let crossOriginUrl = + "http://www1.{{host}}:{{ports[http][0]}}/content-security-policy/frame-src/support/frame.html"; + + promise_test(async test => { + let iframe = document.createElement("iframe"); + document.body.appendChild(iframe); + + for(let hash of ["#0", "#1"]) { + let violation = new Promise(resolve => { + window.addEventListener('securitypolicyviolation', resolve); + }); + iframe.src = crossOriginUrl + hash; + await violation; + } + }, "Same-document navigation in an iframe blocked by CSP frame-src"); +</script> +</html> |