mirror of
https://gitlab.winehq.org/wine/wine-gecko.git
synced 2024-09-13 09:24:08 -07:00
f8962d36e5
--HG-- rename : content/base/test/file_CSP.css => content/base/test/csp/file_CSP.css rename : content/base/test/file_CSP.sjs => content/base/test/csp/file_CSP.sjs rename : content/base/test/file_CSP_bug663567.xsl => content/base/test/csp/file_CSP_bug663567.xsl rename : content/base/test/file_CSP_bug663567_allows.xml => content/base/test/csp/file_CSP_bug663567_allows.xml rename : content/base/test/file_CSP_bug663567_allows.xml^headers^ => content/base/test/csp/file_CSP_bug663567_allows.xml^headers^ rename : content/base/test/file_CSP_bug663567_blocks.xml => content/base/test/csp/file_CSP_bug663567_blocks.xml rename : content/base/test/file_CSP_bug663567_blocks.xml^headers^ => content/base/test/csp/file_CSP_bug663567_blocks.xml^headers^ rename : content/base/test/file_CSP_bug802872.html => content/base/test/csp/file_CSP_bug802872.html rename : content/base/test/file_CSP_bug802872.html^headers^ => content/base/test/csp/file_CSP_bug802872.html^headers^ rename : content/base/test/file_CSP_bug802872.js => content/base/test/csp/file_CSP_bug802872.js rename : content/base/test/file_CSP_bug802872.sjs => content/base/test/csp/file_CSP_bug802872.sjs rename : content/base/test/file_CSP_bug885433_allows.html => content/base/test/csp/file_CSP_bug885433_allows.html rename : content/base/test/file_CSP_bug885433_allows.html^headers^ => content/base/test/csp/file_CSP_bug885433_allows.html^headers^ rename : content/base/test/file_CSP_bug885433_blocks.html => content/base/test/csp/file_CSP_bug885433_blocks.html rename : content/base/test/file_CSP_bug885433_blocks.html^headers^ => content/base/test/csp/file_CSP_bug885433_blocks.html^headers^ rename : content/base/test/file_CSP_bug888172.html => content/base/test/csp/file_CSP_bug888172.html rename : content/base/test/file_CSP_bug888172.sjs => content/base/test/csp/file_CSP_bug888172.sjs rename : content/base/test/file_CSP_evalscript_main.html => content/base/test/csp/file_CSP_evalscript_main.html rename : content/base/test/file_CSP_evalscript_main.html^headers^ => content/base/test/csp/file_CSP_evalscript_main.html^headers^ rename : content/base/test/file_CSP_evalscript_main.js => content/base/test/csp/file_CSP_evalscript_main.js rename : content/base/test/file_CSP_evalscript_main_allowed.js => content/base/test/csp/file_CSP_evalscript_main_allowed.js rename : content/base/test/file_CSP_evalscript_main_allowed_getCRMFRequest.js => content/base/test/csp/file_CSP_evalscript_main_allowed_getCRMFRequest.js rename : content/base/test/file_CSP_evalscript_main_getCRMFRequest.html => content/base/test/csp/file_CSP_evalscript_main_getCRMFRequest.html rename : content/base/test/file_CSP_evalscript_main_getCRMFRequest.html^headers^ => content/base/test/csp/file_CSP_evalscript_main_getCRMFRequest.html^headers^ rename : content/base/test/file_CSP_evalscript_main_getCRMFRequest.js => content/base/test/csp/file_CSP_evalscript_main_getCRMFRequest.js rename : content/base/test/file_CSP_evalscript_main_spec_compliant.html => content/base/test/csp/file_CSP_evalscript_main_spec_compliant.html rename : content/base/test/file_CSP_evalscript_main_spec_compliant.html^headers^ => content/base/test/csp/file_CSP_evalscript_main_spec_compliant.html^headers^ rename : content/base/test/file_CSP_evalscript_main_spec_compliant_allowed.html => content/base/test/csp/file_CSP_evalscript_main_spec_compliant_allowed.html rename : content/base/test/file_CSP_evalscript_main_spec_compliant_allowed.html^headers^ => content/base/test/csp/file_CSP_evalscript_main_spec_compliant_allowed.html^headers^ rename : content/base/test/file_CSP_evalscript_main_spec_compliant_allowed_getCRMFRequest.html => content/base/test/csp/file_CSP_evalscript_main_spec_compliant_allowed_getCRMFRequest.html rename : content/base/test/file_CSP_evalscript_main_spec_compliant_allowed_getCRMFRequest.html^headers^ => content/base/test/csp/file_CSP_evalscript_main_spec_compliant_allowed_getCRMFRequest.html^headers^ rename : content/base/test/file_CSP_evalscript_main_spec_compliant_getCRMFRequest.html => content/base/test/csp/file_CSP_evalscript_main_spec_compliant_getCRMFRequest.html rename : content/base/test/file_CSP_evalscript_main_spec_compliant_getCRMFRequest.html^headers^ => content/base/test/csp/file_CSP_evalscript_main_spec_compliant_getCRMFRequest.html^headers^ rename : content/base/test/file_CSP_evalscript_no_CSP_at_all.html => content/base/test/csp/file_CSP_evalscript_no_CSP_at_all.html rename : content/base/test/file_CSP_evalscript_no_CSP_at_all.html^headers^ => content/base/test/csp/file_CSP_evalscript_no_CSP_at_all.html^headers^ rename : content/base/test/file_CSP_evalscript_no_CSP_at_all.js => content/base/test/csp/file_CSP_evalscript_no_CSP_at_all.js rename : content/base/test/file_CSP_frameancestors.sjs => content/base/test/csp/file_CSP_frameancestors.sjs rename : content/base/test/file_CSP_frameancestors_main.html => content/base/test/csp/file_CSP_frameancestors_main.html rename : content/base/test/file_CSP_frameancestors_main.js => content/base/test/csp/file_CSP_frameancestors_main.js rename : content/base/test/file_CSP_frameancestors_main_spec_compliant.html => content/base/test/csp/file_CSP_frameancestors_main_spec_compliant.html rename : content/base/test/file_CSP_frameancestors_main_spec_compliant.js => content/base/test/csp/file_CSP_frameancestors_main_spec_compliant.js rename : content/base/test/file_CSP_frameancestors_spec_compliant.sjs => content/base/test/csp/file_CSP_frameancestors_spec_compliant.sjs rename : content/base/test/file_CSP_inlinescript_main.html => content/base/test/csp/file_CSP_inlinescript_main.html rename : content/base/test/file_CSP_inlinescript_main.html^headers^ => content/base/test/csp/file_CSP_inlinescript_main.html^headers^ rename : content/base/test/file_CSP_inlinescript_main_spec_compliant.html => content/base/test/csp/file_CSP_inlinescript_main_spec_compliant.html rename : content/base/test/file_CSP_inlinescript_main_spec_compliant.html^headers^ => content/base/test/csp/file_CSP_inlinescript_main_spec_compliant.html^headers^ rename : content/base/test/file_CSP_inlinescript_main_spec_compliant_allowed.html => content/base/test/csp/file_CSP_inlinescript_main_spec_compliant_allowed.html rename : content/base/test/file_CSP_inlinescript_main_spec_compliant_allowed.html^headers^ => content/base/test/csp/file_CSP_inlinescript_main_spec_compliant_allowed.html^headers^ rename : content/base/test/file_CSP_inlinestyle_main.html => content/base/test/csp/file_CSP_inlinestyle_main.html rename : content/base/test/file_CSP_inlinestyle_main.html^headers^ => content/base/test/csp/file_CSP_inlinestyle_main.html^headers^ rename : content/base/test/file_CSP_inlinestyle_main_spec_compliant.html => content/base/test/csp/file_CSP_inlinestyle_main_spec_compliant.html rename : content/base/test/file_CSP_inlinestyle_main_spec_compliant.html^headers^ => content/base/test/csp/file_CSP_inlinestyle_main_spec_compliant.html^headers^ rename : content/base/test/file_CSP_inlinestyle_main_spec_compliant_allowed.html => content/base/test/csp/file_CSP_inlinestyle_main_spec_compliant_allowed.html rename : content/base/test/file_CSP_inlinestyle_main_spec_compliant_allowed.html^headers^ => content/base/test/csp/file_CSP_inlinestyle_main_spec_compliant_allowed.html^headers^ rename : content/base/test/file_CSP_main.html => content/base/test/csp/file_CSP_main.html rename : content/base/test/file_CSP_main.html^headers^ => content/base/test/csp/file_CSP_main.html^headers^ rename : content/base/test/file_CSP_main.js => content/base/test/csp/file_CSP_main.js rename : content/base/test/file_CSP_main_spec_compliant.html => content/base/test/csp/file_CSP_main_spec_compliant.html rename : content/base/test/file_CSP_main_spec_compliant.html^headers^ => content/base/test/csp/file_CSP_main_spec_compliant.html^headers^ rename : content/base/test/file_CSP_main_spec_compliant.js => content/base/test/csp/file_CSP_main_spec_compliant.js rename : content/base/test/file_bothCSPheaders.html => content/base/test/csp/file_bothCSPheaders.html rename : content/base/test/file_bothCSPheaders.html^headers^ => content/base/test/csp/file_bothCSPheaders.html^headers^ rename : content/base/test/file_csp_bug768029.html => content/base/test/csp/file_csp_bug768029.html rename : content/base/test/file_csp_bug768029.sjs => content/base/test/csp/file_csp_bug768029.sjs rename : content/base/test/file_csp_bug773891.html => content/base/test/csp/file_csp_bug773891.html rename : content/base/test/file_csp_bug773891.sjs => content/base/test/csp/file_csp_bug773891.sjs rename : content/base/test/file_csp_redirects_main.html => content/base/test/csp/file_csp_redirects_main.html rename : content/base/test/file_csp_redirects_page.sjs => content/base/test/csp/file_csp_redirects_page.sjs rename : content/base/test/file_csp_redirects_resource.sjs => content/base/test/csp/file_csp_redirects_resource.sjs rename : content/base/test/test_CSP.html => content/base/test/csp/test_CSP.html rename : content/base/test/test_CSP_bug663567.html => content/base/test/csp/test_CSP_bug663567.html rename : content/base/test/test_CSP_bug802872.html => content/base/test/csp/test_CSP_bug802872.html rename : content/base/test/test_CSP_bug885433.html => content/base/test/csp/test_CSP_bug885433.html rename : content/base/test/test_CSP_bug888172.html => content/base/test/csp/test_CSP_bug888172.html rename : content/base/test/test_CSP_evalscript.html => content/base/test/csp/test_CSP_evalscript.html rename : content/base/test/test_CSP_evalscript_getCRMFRequest.html => content/base/test/csp/test_CSP_evalscript_getCRMFRequest.html rename : content/base/test/test_CSP_frameancestors.html => content/base/test/csp/test_CSP_frameancestors.html rename : content/base/test/test_CSP_inlinescript.html => content/base/test/csp/test_CSP_inlinescript.html rename : content/base/test/test_CSP_inlinestyle.html => content/base/test/csp/test_CSP_inlinestyle.html rename : content/base/test/test_bothCSPheaders.html => content/base/test/csp/test_bothCSPheaders.html rename : content/base/test/chrome/test_csp_bug768029.html => content/base/test/csp/test_csp_bug768029.html rename : content/base/test/chrome/test_csp_bug773891.html => content/base/test/csp/test_csp_bug773891.html rename : content/base/test/test_csp_redirects.html => content/base/test/csp/test_csp_redirects.html
127 lines
4.4 KiB
JavaScript
127 lines
4.4 KiB
JavaScript
// some javascript for the CSP eval() tests
|
|
|
|
function logResult(str, passed) {
|
|
var elt = document.createElement('div');
|
|
var color = passed ? "#cfc;" : "#fcc";
|
|
elt.setAttribute('style', 'background-color:' + color + '; width:100%; border:1px solid black; padding:3px; margin:4px;');
|
|
elt.innerHTML = str;
|
|
document.body.appendChild(elt);
|
|
}
|
|
|
|
window._testResults = {};
|
|
|
|
// callback for when stuff is allowed by CSP
|
|
var onevalexecuted = (function(window) {
|
|
return function(shouldrun, what, data) {
|
|
window._testResults[what] = "ran";
|
|
window.parent.scriptRan(shouldrun, what, data);
|
|
logResult((shouldrun ? "PASS: " : "FAIL: ") + what + " : " + data, shouldrun);
|
|
};})(window);
|
|
|
|
// callback for when stuff is blocked
|
|
var onevalblocked = (function(window) {
|
|
return function(shouldrun, what, data) {
|
|
window._testResults[what] = "blocked";
|
|
window.parent.scriptBlocked(shouldrun, what, data);
|
|
logResult((shouldrun ? "FAIL: " : "PASS: ") + what + " : " + data, !shouldrun);
|
|
};})(window);
|
|
|
|
|
|
// Defer until document is loaded so that we can write the pretty result boxes
|
|
// out.
|
|
addEventListener('load', function() {
|
|
// setTimeout(String) test -- mutate something in the window._testResults
|
|
// obj, then check it.
|
|
{
|
|
var str_setTimeoutWithStringRan = 'onevalexecuted(false, "setTimeout(String)", "setTimeout with a string was enabled.");';
|
|
function fcn_setTimeoutWithStringCheck() {
|
|
if (this._testResults["setTimeout(String)"] !== "ran") {
|
|
onevalblocked(false, "setTimeout(String)",
|
|
"setTimeout with a string was blocked");
|
|
}
|
|
}
|
|
setTimeout(fcn_setTimeoutWithStringCheck.bind(window), 10);
|
|
setTimeout(str_setTimeoutWithStringRan, 10);
|
|
}
|
|
|
|
// setTimeout(function) test -- mutate something in the window._testResults
|
|
// obj, then check it.
|
|
{
|
|
function fcn_setTimeoutWithFunctionRan() {
|
|
onevalexecuted(true, "setTimeout(function)",
|
|
"setTimeout with a function was enabled.")
|
|
}
|
|
function fcn_setTimeoutWithFunctionCheck() {
|
|
if (this._testResults["setTimeout(function)"] !== "ran") {
|
|
onevalblocked(true, "setTimeout(function)",
|
|
"setTimeout with a function was blocked");
|
|
}
|
|
}
|
|
setTimeout(fcn_setTimeoutWithFunctionRan.bind(window), 10);
|
|
setTimeout(fcn_setTimeoutWithFunctionCheck.bind(window), 10);
|
|
}
|
|
|
|
// eval() test -- should throw exception as per spec
|
|
try {
|
|
eval('onevalexecuted(false, "eval(String)", "eval() was enabled.");');
|
|
} catch (e) {
|
|
onevalblocked(false, "eval(String)",
|
|
"eval() was blocked");
|
|
}
|
|
|
|
// eval(foo,bar) test -- should throw exception as per spec
|
|
try {
|
|
eval('onevalexecuted(false, "eval(String,scope)", "eval() was enabled.");',1);
|
|
} catch (e) {
|
|
onevalblocked(false, "eval(String,object)",
|
|
"eval() with scope was blocked");
|
|
}
|
|
|
|
// [foo,bar].sort(eval) test -- should throw exception as per spec
|
|
try {
|
|
['onevalexecuted(false, "[String, obj].sort(eval)", "eval() was enabled.");',1].sort(eval);
|
|
} catch (e) {
|
|
onevalblocked(false, "[String, obj].sort(eval)",
|
|
"eval() with scope via sort was blocked");
|
|
}
|
|
|
|
// [].sort.call([foo,bar], eval) test -- should throw exception as per spec
|
|
try {
|
|
[].sort.call(['onevalexecuted(false, "[String, obj].sort(eval)", "eval() was enabled.");',1], eval);
|
|
} catch (e) {
|
|
onevalblocked(false, "[].sort.call([String, obj], eval)",
|
|
"eval() with scope via sort/call was blocked");
|
|
}
|
|
|
|
// new Function() test -- should throw exception as per spec
|
|
try {
|
|
var fcn = new Function('onevalexecuted(false, "new Function(String)", "new Function(String) was enabled.");');
|
|
fcn();
|
|
} catch (e) {
|
|
onevalblocked(false, "new Function(String)",
|
|
"new Function(String) was blocked.");
|
|
}
|
|
|
|
// setTimeout(eval, 0, str)
|
|
{
|
|
// error is not catchable here, instead, we're going to side-effect
|
|
// 'worked'.
|
|
var worked = false;
|
|
|
|
setTimeout(eval, 0, 'worked = true');
|
|
setTimeout(function(worked) {
|
|
if (worked) {
|
|
onevalexecuted(false, "setTimeout(eval, 0, str)",
|
|
"setTimeout(eval, 0, string) was enabled.");
|
|
} else {
|
|
onevalblocked(false, "setTimeout(eval, 0, str)",
|
|
"setTimeout(eval, 0, str) was blocked.");
|
|
}
|
|
}, 0, worked);
|
|
}
|
|
|
|
}, false);
|
|
|
|
|
|
|