Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(479)

Side by Side Diff: LayoutTests/http/tests/security/dataURL/xss-DENIED-from-data-url-in-foreign-domain-subframe-expected.txt

Issue 19932002: Throw exceptions on all failed cross-origin access checks. (Closed) Base URL: svn://svn.chromium.org/blink/trunk
Patch Set: test. Created 7 years, 5 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch | Annotate | Revision Log
OLDNEW
1 CONSOLE MESSAGE: Blocked a frame with origin "null" from accessing a frame with origin "http://127.0.0.1:8000". The frame requesting access has a protocol of " data", the frame being accessed has a protocol of "http". Protocols must match.
2
3 ALERT: PASS: Exception thrown successfully. 1 ALERT: PASS: Exception thrown successfully.
4 The scenario for this test is that you have an iframe with content from a foreig n domain. In that foreign content is an iframe which loads a data: URL. This tes ts that the data: URL loaded iframe does not have access to the main frame using top.document. 2 The scenario for this test is that you have an iframe with content from a foreig n domain. In that foreign content is an iframe which loads a data: URL. This tes ts that the data: URL loaded iframe does not have access to the main frame using top.document.
5 3
6 Pass: Cross frame access from a data: URL on a different domain was denied. 4 Pass: Cross frame access from a data: URL on a different domain was denied.
7 5
8 6
9 7
10 -------- 8 --------
11 Frame: 'aFrame' 9 Frame: 'aFrame'
12 -------- 10 --------
13 Inner iframe on a foreign domain. 11 Inner iframe on a foreign domain.
14 12
15 13
16 14
17 -------- 15 --------
18 Frame: 'aFrame' 16 Frame: 'aFrame'
19 -------- 17 --------
20 Inner-inner iframe. This iframe (which is data: URL and whose parent is on a for eign domain) is the frame attempting to access the main frame. It should not hav e access to it. 18 Inner-inner iframe. This iframe (which is data: URL and whose parent is on a for eign domain) is the frame attempting to access the main frame. It should not hav e access to it.
OLDNEW

Powered by Google App Engine
This is Rietveld 408576698