Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(23)

Unified Diff: third_party/WebKit/LayoutTests/http/tests/security/mixedContent/insecure-localhost-allowed.https.html

Issue 1931063004: Stop blocking 'http://127.0.0.1/' as mixed content. (Closed) Base URL: https://chromium.googlesource.com/chromium/src.git@master
Patch Set: Ugh. Created 4 years, 6 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
Index: third_party/WebKit/LayoutTests/http/tests/security/mixedContent/insecure-localhost-allowed.https.html
diff --git a/third_party/WebKit/LayoutTests/http/tests/security/mixedContent/insecure-localhost-allowed.https.html b/third_party/WebKit/LayoutTests/http/tests/security/mixedContent/insecure-localhost-allowed.https.html
new file mode 100644
index 0000000000000000000000000000000000000000..82e002bdade9799224a5fc3ed32c67e16c67fc3f
--- /dev/null
+++ b/third_party/WebKit/LayoutTests/http/tests/security/mixedContent/insecure-localhost-allowed.https.html
@@ -0,0 +1,24 @@
+<!DOCTYPE html>
+<html>
+<body>
+ <script src="/resources/testharness.js"></script>
+ <script src="/resources/testharnessreport.js"></script>
+ <script>
+ if (window.testRunner)
+ testRunner.overridePreference("WebKitAllowRunningInsecureContent", false);
+
+ async_test(t => {
+ fetch("http://127.0.0.1:8000/xmlhttprequest/resources/access-control-allow-lists.php?origin=*", {method: "POST"})
+ .then(t.step_func(r => r.json()))
+ .then(t.step_func_done(j => assert_equals("127.0.0.1:8000", j.host)))
+ .catch(t.unreached_func("Fetch should not be blocked."));
+ }, "Fetching 'http://127.0.0.1/' should not be blocked.");
+
+ async_test(t => {
+ fetch("http://example.test:8000/xmlhttprequest/resources/access-control-allow-lists.php?origin=*", {method: "POST"})
+ .then(t.unreached_func("Fetch should be blocked."))
+ .catch(t.step_func_done(e => assert_equals(e.message, "Failed to fetch")));
+ }, "Fetching 'http://example.test/' should be blocked.");
+ </script>
+</body>
+</html>

Powered by Google App Engine
This is Rietveld 408576698