Files
sousa-gecko/testing/web-platform/tests/storage-access-api/resources/iframe-creation.sub.html
T
Janice Liu 394d817121 Bug 1961795 [wpt PR 52029] - [Blob URL] Tighten StorageAccess Implementation with Partitioning Blob URL, a=testonly
Automatic update from web-platform-tests
[Blob URL] Tighten StorageAccess Implementation with Partitioning Blob URL

When a third-party context has been granted a StorageAccessHandle, it
should allow it to access first-party Blob URLs but not Blob URLs from a
different third-party context. Initially, both contexts were being
bypassed when StorageAccessHandle was granted.

Bug: 399308041
Change-Id: Ic5ebc1fcf4452c43d9206b2e20481a091e4f4ad0
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/6430562
Reviewed-by: Dominic Farolino <dom@chromium.org>
Reviewed-by: Andrew Williams <awillia@chromium.org>
Commit-Queue: Janice Liu <janiceliu@chromium.org>
Reviewed-by: Mingyu Lei <leimy@chromium.org>
Auto-Submit: Janice Liu <janiceliu@chromium.org>
Cr-Commit-Position: refs/heads/main@{#1447846}

--

wpt-commits: 70c3b97c076a1c7b8478f80dcb5b5e390a02e050
wpt-pr: 52029
2025-04-23 10:43:51 +00:00

21 lines
587 B
HTML

<!DOCTYPE html>
<meta charset="utf-8">
<body>
<script>
'use strict';
const iframe = document.createElement("iframe");
iframe.src = "https://{{hosts[][]}}:{{ports[https][0]}}/storage-access-api/resources/blob-url-creation.html";
document.body.appendChild(iframe);
// Send the blob URL back to the opener.
window.addEventListener("message", async e => {
if (e.data.type !== "blobURL") {
return;
}
const blob_url = e.data.message;
window.opener.postMessage({ type: "blobURL", message: blob_url }, "*");
});
</script>
</body>