Automatic update from web-platform-tests [Blob URL] Tighten StorageAccess Implementation with Partitioning Blob URL When a third-party context has been granted a StorageAccessHandle, it should allow it to access first-party Blob URLs but not Blob URLs from a different third-party context. Initially, both contexts were being bypassed when StorageAccessHandle was granted. Bug: 399308041 Change-Id: Ic5ebc1fcf4452c43d9206b2e20481a091e4f4ad0 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/6430562 Reviewed-by: Dominic Farolino <dom@chromium.org> Reviewed-by: Andrew Williams <awillia@chromium.org> Commit-Queue: Janice Liu <janiceliu@chromium.org> Reviewed-by: Mingyu Lei <leimy@chromium.org> Auto-Submit: Janice Liu <janiceliu@chromium.org> Cr-Commit-Position: refs/heads/main@{#1447846} -- wpt-commits: 70c3b97c076a1c7b8478f80dcb5b5e390a02e050 wpt-pr: 52029
21 lines
587 B
HTML
21 lines
587 B
HTML
<!DOCTYPE html>
|
|
<meta charset="utf-8">
|
|
<body>
|
|
<script>
|
|
'use strict';
|
|
|
|
const iframe = document.createElement("iframe");
|
|
iframe.src = "https://{{hosts[][]}}:{{ports[https][0]}}/storage-access-api/resources/blob-url-creation.html";
|
|
document.body.appendChild(iframe);
|
|
|
|
// Send the blob URL back to the opener.
|
|
window.addEventListener("message", async e => {
|
|
if (e.data.type !== "blobURL") {
|
|
return;
|
|
}
|
|
const blob_url = e.data.message;
|
|
window.opener.postMessage({ type: "blobURL", message: blob_url }, "*");
|
|
});
|
|
</script>
|
|
</body>
|