Automatic update from web-platform-tests Propagate attr() taint flag to CSSDefaultNonInterpolableValue Previously, if an `attr()` function was used in a custom property and underwent a CSS transition, the tainted flag could be lost. This patch ensures that the `is_attr_tainted` flag is properly propagated to `CSSDefaultNonInterpolableValue` when transitioning registered custom properties of type `<string>`. Fixed: 501801823 Change-Id: I015539cf9fdaabd94e35aa5be5582e5dab7a2f4f Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7772751 Reviewed-by: Anders Hartvoll Ruud <andruud@chromium.org> Commit-Queue: Munira Tursunova <moonira@google.com> Cr-Commit-Position: refs/heads/main@{#1616868} -- wpt-commits: 2cefa3f20d8aae19a3c6285ff3cafa74ed9fb1a2 wpt-pr: 59325
35 lines
897 B
HTML
35 lines
897 B
HTML
<!DOCTYPE html>
|
|
<title>CSS Values and Units Test: attr() security limitations</title>
|
|
<link rel="help" href="https://drafts.csswg.org/css-values-5/#attr-security">
|
|
<script src="/resources/testharness.js"></script>
|
|
<script src="/resources/testharnessreport.js"></script>
|
|
|
|
<style>
|
|
@property --s {
|
|
syntax: "<string>";
|
|
inherits: false;
|
|
initial-value: "x";
|
|
}
|
|
#attr {
|
|
--s: attr(href);
|
|
transition: --s 10s allow-discrete -9s;
|
|
background-image: image-set(var(--s));
|
|
}
|
|
@starting-style {
|
|
#attr { --s: "x"; }
|
|
}
|
|
</style>
|
|
|
|
<html>
|
|
<body>
|
|
<div id="attr" href="https://does-not-exist.test/404.png">div</div>
|
|
</body>
|
|
</html>
|
|
|
|
<script>
|
|
var elem = document.getElementById("attr");
|
|
test(() => {
|
|
assert_equals(window.getComputedStyle(elem).getPropertyValue("background-image"), 'none');
|
|
}, `background-image value should be attr-tainted`);
|
|
</script>
|