Files
sousa-gecko/testing/web-platform/tests/preload/preload-csp.sub.html
T
Eemeli Aro 47278ee8b8 Bug 2006657 [wpt PR 56812] - Add tests for text modules, a=testonly
Automatic update from web-platform-tests
Add tests for text modules

This is to support the spec changes in:

- https://github.com/tc39/proposal-import-text
- https://github.com/whatwg/html/pull/11933
- https://github.com/whatwg/fetch/pull/1898
- https://github.com/w3c/webappsec-csp/pull/794
--

wpt-commits: 5419f98d72f4b1ae49980581a6a66710d6a3dee7
wpt-pr: 56812
2026-04-17 08:35:15 +00:00

38 lines
2.0 KiB
HTML

<!DOCTYPE html>
<meta http-equiv="Content-Security-Policy" content="script-src 'self' 'unsafe-inline'; font-src 'none'; style-src 'none'; img-src 'none'; media-src 'none';">
<title>Makes sure that preload requests respect CSP</title>
<script src="/resources/testharness.js"></script>
<script src="/resources/testharnessreport.js"></script>
<script src="/common/utils.js"></script>
<script src="/preload/resources/preload_helper.js"></script>
<link rel=preload href="http://{{host}}:{{ports[http][1]}}/preload/resources/stash-put.py?key={{uuid()}}" as=style>
<link rel=preload href="/preload/resources/stash-put.py?key={{uuid()}}" as=style>
<link rel=preload href="/preload/resources/stash-put.py?key={{uuid()}}" as=json>
<link rel=preload href="/preload/resources/stash-put.py?key={{uuid()}}" as=text>
<link rel=preload href="/preload/resources/stash-put.py?key={{uuid()}}" as=image>
<link rel=preload href="/preload/resources/stash-put.py?key={{uuid()}}" as=font crossorigin>
<link rel=preload href="/preload/resources/stash-put.py?key={{uuid()}}" as=video>
<link rel=preload href="/preload/resources/stash-put.py?key={{uuid()}}" as=audio>
<link rel=preload href="/preload/resources/stash-put.py?key={{uuid()}}" as=track>
<link rel=preload href="/preload/resources/stash-put.py?key={{uuid()}}" as=foobarxmlthing>
<link rel=preload href="/preload/resources/stash-put.py?key={{uuid()}}">
<body>
<script>
promise_test(async (t) => {
verifyPreloadAndRTSupport();
const keys = [];
const links = document.querySelectorAll('link');
for (const link of links) {
if (link.rel === 'preload') {
const r = /\?key=([a-zA-Z0-9\-]+)$/;
keys.push([link.href, link.as, link.href.match(r)[1]]);
}
}
await new Promise((resolve) => step_timeout(resolve, 3000));
for (const [href, type, key] of keys) {
assert_false(await hasArrivedAtServer(key), `Preload with href ${href}, type ${type} and key ${key} should not have arrived at the server.`);
}
}, 'Preload requests are blocked by CSP.');
</script>