Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(360)

Side by Side Diff: chrome/test/data/extensions/api_test/sandboxed_pages_csp/main.js

Issue 2563843002: Restrict app sandbox's CSP to disallow loading web content in them. (Closed)
Patch Set: address comments + rework CL + StringPieces Created 4 years ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch
OLDNEW
(Empty)
1 // Copyright 2016 The Chromium Authors. All rights reserved.
2 // Use of this source code is governed by a BSD-style license that can be
3 // found in the LICENSE file.
4
5 var LOCAL_FILE_NAME = 'local_frame.html';
6 var REMOTE_FILE_NAME = 'remote_frame.html';
7
8 onmessage = function(e) {
9 var data = JSON.parse(e.data);
10 var message = data[0];
11 if (message != 'loaded')
12 return;
13
14 var loadedFileName = data[1];
15 var succeeded = data[2];
16 var expectSuccess = loadedFileName === LOCAL_FILE_NAME;
17 chrome.test.assertEq(expectSuccess, succeeded);
18 chrome.test.succeed();
19 };
20
21 var loadIframeContentInSandboxedPage = function(url, fileName) {
22 var sandboxedFrame = document.createElement('iframe');
23 sandboxedFrame.src = 'sandboxed.html';
24 sandboxedFrame.onload = function() {
25 sandboxedFrame.contentWindow.postMessage(
26 JSON.stringify(['load', url, fileName]), '*');
27 sandboxedFrame.onload = null;
28 };
29 document.body.appendChild(sandboxedFrame);
30 };
31
32 onload = function() {
33 chrome.test.getConfig(function(config) {
34 chrome.test.runTests([
35 function sandboxedFrameLocalContentPasses() {
36 // Response is received in |onmessage|.
37 loadIframeContentInSandboxedPage(LOCAL_FILE_NAME, LOCAL_FILE_NAME);
38 },
39 function sandboxedFrameWebContentFails() {
40 var url = 'http://localhost:' + config.testServer.port +
41 '/extensions/api_test/sandboxed_pages_web_content/' +
42 REMOTE_FILE_NAME;
43 // Response is received in |onmessage|.
44 loadIframeContentInSandboxedPage(url, REMOTE_FILE_NAME);
45 }
46 ]);
47 });
48 };
OLDNEW

Powered by Google App Engine
This is Rietveld 408576698