blob: 1e35b75e0b9eea9f80ae3dbc7bcd7338eaea82d4 [file] [log] [blame]
CONSOLE MESSAGE: line 1: Unsafe JavaScript attempt to access frame with URL http://localhost:8000/security/dataURL/resources/foreign-domain-data-url-accessee-iframe.html from frame with URL http://127.0.0.1:8000/security/dataURL/xss-DENIED-to-data-url-in-foreign-domain-subframe.html. Domains, protocols and ports must match.
The scenario for this test is that you have an iframe with content from a foreign domain. In that foreign content is an iframe which loads a data: URL. This tests that this main document does not have access to that data: URL loaded iframe.
PASS: Cross frame access to a data: URL embed in a frame on a foreign domain denied!
--------
Frame: '<!--framePath //<!--frame0-->-->'
--------
Inner iframe on a foreign domain.
--------
Frame: 'aFrame'
--------
PASS: Cross frame access from a frame on a foreign domain denied!
Inner-inner iframe. This iframe (which is data: URL and whose parent is on a foreign domain) is the frame that the main frame is trying to access. It should not have access to it.
--------
Frame: 'flag'
--------