Files
sousa-gecko/testing/web-platform/tests/client-hints/clear-site-data/clear-site-data-client-hints-third-party.https.sub.html
T
Ari Chivukula c28a9fa18d Bug 2043646 [wpt PR 60257] - [Clear-Site-Data] Only clear client-hints for top-frames, a=testonly
Automatic update from web-platform-tests
[Clear-Site-Data] Only clear client-hints for top-frames

We shouldn't allow third-party iframes to clear first-party data they
lack access to. Client hint cache is only read for the top frame.

Fixed: 517474638
Change-Id: Iecbbd58e9bc1d6b88428ba1772f4451c4f25c395
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7881484
Commit-Queue: Ari Chivukula <arichiv@chromium.org>
Auto-Submit: Ari Chivukula <arichiv@chromium.org>
Reviewed-by: Charlie Reis <creis@chromium.org>
Cr-Commit-Position: refs/heads/main@{#1638165}

--

wpt-commits: 75ba8ba8ae5c686049a9c2f78fc4a35a0bd66fa0
wpt-pr: 60257
2026-06-02 10:27:19 +00:00

39 lines
1.6 KiB
HTML

<!DOCTYPE html>
<body>
<script src="/resources/testharness.js"></script>
<script src="/resources/testharnessreport.js"></script>
<script>
// Here's the set-up for this test:
// Step 1 (first window) Open new window to verify that hints were set.
// Step 2 (second window) Alert first window of client hints present.
// Step 3 (first window) Asserts client hints were present.
// Step 4 (first window) Navigate other window to a third-party with an iframe.
// Step 5 (second window) Attempt to reset client hints in that iframe.
// Step 6 (second window) Navigate top frame to a page that can check client hints still sent.
// Step 7 (second window) Alert first window of client hints present.
// Step 8 (first window) Asserts client hints was present.
async_test(t => {
var new_window;
// Step 3
window.addEventListener("message", t.step_func(e => {
assert_equals(e.data, "HadDeviceMemory");
// Step 8
window.addEventListener("message", t.step_func(e => {
assert_equals(e.data, "HadDeviceMemory");
t.done();
}), {once: true});
// Step 4
new_window.location.href = "https://{{hosts[alt][]}}:{{ports[https][0]}}/client-hints/clear-site-data/resources/clear-site-data-iframe.sub.py?target=clientHints";
}), {once: true});
// Step 1
new_window = window.open("/client-hints/clear-site-data/resources/check-client-hints.py");
t.add_cleanup(() => new_window.close());
}, "Clear-Site-Data for clientHints in third-party context should not remove all client hints.");
</script>
</body>
</html>