diff options
Diffstat (limited to 'testing/web-platform/tests/reporting/same-origin-report-credentials.https.sub.html')
-rw-r--r-- | testing/web-platform/tests/reporting/same-origin-report-credentials.https.sub.html | 39 |
1 files changed, 39 insertions, 0 deletions
diff --git a/testing/web-platform/tests/reporting/same-origin-report-credentials.https.sub.html b/testing/web-platform/tests/reporting/same-origin-report-credentials.https.sub.html new file mode 100644 index 0000000000..cd93bd601b --- /dev/null +++ b/testing/web-platform/tests/reporting/same-origin-report-credentials.https.sub.html @@ -0,0 +1,39 @@ +<!DOCTYPE HTML> +<html> +<head> + <title>Test that reports are sent with credentials to same-origin endpoints</title> + <script src='/resources/testharness.js'></script> + <script src='/resources/testharnessreport.js'></script> + <script src='resources/report-helper.js'></script> +</head> +<body> + <script> + const base_url = `${location.protocol}//${location.host}`; + const endpoint = `${base_url}/reporting/resources/report.py`; + const id = '320db941-960a-4529-8c4a-24aeb6739309'; + + promise_test(async t => { + // Set credentials, and set up test to clear them afterwards. + await fetch('/cookies/resources/set-cookie.py?name=report&path=%2F', {mode: 'no-cors', credentials: 'include', cache: 'no-store'}); + t.add_cleanup(() => fetch("/cookies/resources/set.py?report=; path=%2F; expires=Thu, 01 Jan 1970 00:00:01 GMT")); + + // Trigger a CSP error. + await new Promise(resolve => { + const img = document.createElement('img'); + img.src = "/reporting/resources/fail.png"; + img.addEventListener('error', resolve); + document.body.appendChild(img); + }); + + // Wait for report to be received. + const reports = await pollReports(endpoint, id); + checkReportExists(reports, 'csp-violation', location.href); + + // Validate that credentials were sent to same-origin endpoint. + const cookies = await pollCookies(endpoint, id); + assert_true('report' in cookies, "Credentials were present in report"); + assert_equals(cookies.report, "[report=1]", "Credential value was correct"); + }, "Reporting endpoints received credentials."); + </script> +</body> +</html> |