Chromium Code Reviews| Index: third_party/WebKit/LayoutTests/http/tests/security/secureContexts/authenticated_sandbox.html |
| diff --git a/third_party/WebKit/LayoutTests/http/tests/security/secureContexts/authenticated_sandbox.html b/third_party/WebKit/LayoutTests/http/tests/security/secureContexts/authenticated_sandbox.html |
| new file mode 100644 |
| index 0000000000000000000000000000000000000000..8a93375d726cb88f0cfde9d01b1f2f935c21f3be |
| --- /dev/null |
| +++ b/third_party/WebKit/LayoutTests/http/tests/security/secureContexts/authenticated_sandbox.html |
| @@ -0,0 +1,38 @@ |
| +<!DOCTYPE html> |
| +<html> |
| +<head> |
| + <title>Unauthenticated origin with sandbox iframe is insecure</title> |
|
Mike West
2016/02/25 11:58:11
Nit: s/Unauthenticated/Authenticated/, s/insecure/
estark
2016/03/01 02:59:26
Done.
|
| + <script src="/resources/testharness.js"></script> |
| + <script src="/resources/testharness-helpers.js"></script> |
| + <script src="/resources/testharnessreport.js"></script> |
| + <script src="/resources/get-host-info.js"></script> |
| +</head> |
| +<body> |
| + <script> |
| + if (window.location.origin != get_host_info().AUTHENTICATED_ORIGIN) { |
| + window.location = get_host_info().AUTHENTICATED_ORIGIN + |
| + window.location.pathname; |
| + } else { |
| + test(function () { |
| + assert_equals(window.location.origin, get_host_info().AUTHENTICATED_ORIGIN, "Sanity check the test runner."); |
| + assert_true(window.isSecureContext); |
| + }, "authenticated origin is secure."); |
| + |
| + async_test(function (t) { |
| + var messages = 0; |
| + window.addEventListener("message", t.step_func(function (e) { |
| + assert_true(e.data.isSecureContext); |
| + messages++; |
| + if (messages >= 1) |
| + t.done(); |
| + }), false); |
| + |
| + var i1 = document.createElement("iframe"); |
| + i1.srcdoc = "<iframe src='" + get_host_info().AUTHENTICATED_ORIGIN + "/security/secureContexts/resources/post-securecontext-status.html" + "'></iframe>"; |
|
alexmos
2016/02/26 19:21:57
nit: wrong indent (and line below). Also for othe
estark
2016/03/01 02:59:25
Done.
|
| + i1.sandbox = "allow-scripts"; |
| + document.body.appendChild(i1); |
| + }, "Frames inside sandboxed frames are secure"); |
| + } |
| + </script> |
| +</body> |
| +</html> |