Files
sousa-gecko/testing/web-platform/tests/content-security-policy/inheritance/document-write-iframe.html
T
Vincent Hilla 973d6e2bf6 Bug 2035423 - Revert setting CSP context already on document creation. r=tschuster
StartDocumentLoad calls SetRequestContextWithDocument. Since bug 543435, the
initial about:blank load doesn't go through this code anymore. Therefore, we
added that call also to CreateAboutBlankDocumentViewer. This is advantageous
in general too, because transient documents will have the correct context.
But due to bug 1899512, there are regressions.

This change reverts setting the request context already at document creation.
Instead we match regular loads and set the request context in the corresponding
CompleteInitialAboutBlankLoad.

Differential Revision: https://phabricator.services.mozilla.com/D297337
2026-05-05 14:02:54 +00:00

92 lines
3.2 KiB
HTML

<!DOCTYPE html>
<head>
<meta http-equiv="Content-Security-Policy" content="img-src 'none'">
<script src="/resources/testharness.js"></script>
<script src="/resources/testharnessreport.js"></script>
<title>document.open() does not change Content Security Policies</title>
</head>
<body>
<script>
let message_from = (w) => {
return new Promise((resolve, reject) => {
let onMsg = msg => {
if (msg.source != w)
return;
window.removeEventListener('message', onMsg);
window.removeEventListener('securitypolicyviolation', abort)
resolve(msg.data);
};
// Avoid timeout if violation events occur on the wrong window
let abort = evt => {
window.removeEventListener('message', onMsg);
window.removeEventListener('securitypolicyviolation', abort)
reject("unexpected violation in top window");
}
window.addEventListener('message', onMsg);
window.addEventListener('securitypolicyviolation', abort)
});
};
var documentBody = function(should_load) {
let image = should_load ? "pass.png" : "fail.png";
return `
<script>
function loaded() {
window.top.postMessage("loaded", '*');
};
window.addEventListener('securitypolicyviolation', function(e) {
window.top.postMessage("blocked", '*');
});
</scr`+`ipt>
<img src='/content-security-policy/support/${image}' onload='loaded()'>`;
};
promise_test(async () => {
let iframe = document.createElement('iframe');
let loaded = new Promise(resolve => iframe.onload = resolve);
document.body.appendChild(iframe);
await loaded;
let msg = message_from(iframe.contentWindow);
let doc = iframe.contentWindow.document;
doc.open();
doc.write("<html><body>" + documentBody(false) + "</body></html>");
doc.close();
assert_equals(await msg, "blocked");
}, "document.open() keeps inherited CSPs on initial about:blank.");
promise_test(async () => {
let iframe = document.createElement('iframe');
let loaded = new Promise(resolve => iframe.onload = resolve);
iframe.src = "/common/blank.html";
document.body.appendChild(iframe);
await loaded;
let msg = message_from(iframe.contentWindow);
let doc = iframe.contentWindow.document;
doc.open();
doc.write("<html><body>" + documentBody(true) + "</body></html>");
doc.close();
assert_equals(await msg, "loaded");
}, "document.open() does not change delivered CSPs.");
promise_test(async () => {
let iframe = document.createElement('iframe');
iframe.src = "/common/blank.html";
let loaded = false;
iframe.onload = () => loaded = true;
document.body.appendChild(iframe);
assert_false(loaded, "iframe document should be transient");
let msg = message_from(iframe.contentWindow);
let doc = iframe.contentWindow.document;
doc.open();
doc.write("<html><body>" + documentBody(false) + "</body></html>");
doc.close();
assert_equals(await msg, "blocked");
}, "document.open() keeps inherited CSPs on transient about:blank.");
</script>
</body>
</html>