Automatic update from web-platform-tests Propagate attr() taint flag to CSSDefaultNonInterpolableValue Previously, if an `attr()` function was used in a custom property and underwent a CSS transition, the tainted flag could be lost. This patch ensures that the `is_attr_tainted` flag is properly propagated to `CSSDefaultNonInterpolableValue` when transitioning registered custom properties of type `<string>`. Fixed: 501801823 Change-Id: I015539cf9fdaabd94e35aa5be5582e5dab7a2f4f Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7772751 Reviewed-by: Anders Hartvoll Ruud <andruud@chromium.org> Commit-Queue: Munira Tursunova <moonira@google.com> Cr-Commit-Position: refs/heads/main@{#1616868} -- wpt-commits: 2cefa3f20d8aae19a3c6285ff3cafa74ed9fb1a2 wpt-pr: 59325
52 lines
1.2 KiB
HTML
52 lines
1.2 KiB
HTML
<!DOCTYPE html>
|
|
<title>CSS Values and Units Test: attr() security limitations</title>
|
|
<link rel="help" href="https://drafts.csswg.org/css-values-5/#attr-security">
|
|
<script src="/resources/testharness.js"></script>
|
|
<script src="/resources/testharnessreport.js"></script>
|
|
|
|
<style>
|
|
@property --s {
|
|
syntax: "<string>";
|
|
inherits: false;
|
|
initial-value: "x";
|
|
}
|
|
#attr {
|
|
--s: attr(href);
|
|
animation: 1s anim linear;
|
|
background-image: image-set(var(--s));
|
|
}
|
|
|
|
@keyframes anim {
|
|
from {
|
|
--s: "x";
|
|
}
|
|
to {
|
|
--s: attr(href);
|
|
}
|
|
}
|
|
</style>
|
|
|
|
<html>
|
|
<body>
|
|
<div id="attr" href="https://does-not-exist.test/404.png">div</div>
|
|
</body>
|
|
</html>
|
|
|
|
<script>
|
|
test(() => {
|
|
// during animation
|
|
document.getAnimations().forEach(anim => {
|
|
anim.currentTime = 600;
|
|
});
|
|
var elem = document.getElementById("attr");
|
|
assert_equals(window.getComputedStyle(elem).getPropertyValue("background-image"), 'none');
|
|
|
|
// after animation
|
|
document.getAnimations().forEach(anim => {
|
|
anim.currentTime = 3000;
|
|
});
|
|
var elem = document.getElementById("attr");
|
|
assert_equals(window.getComputedStyle(elem).getPropertyValue("background-image"), 'none');
|
|
});
|
|
</script>
|