<script>

var framesLoaded = 0;
var redirectCodes = new Array();
redirectCodes[0] = "301";
redirectCodes[1] = "302";
redirectCodes[2] = "303";
redirectCodes[3] = "307";

function frameLoaded()
{
    if (++framesLoaded == 4) {
        if (window.testRunner)
            testRunner.notifyDone();
        return;
    }
    
    appendFrame(redirectCodes[framesLoaded]);
}

if (window.testRunner) {
    testRunner.waitUntilDone();
    testRunner.dumpAsText();
    testRunner.dumpChildFramesAsText();
    testRunner.setHandlesAuthenticationChallenges(true);
    testRunner.setAuthenticationUsername("testUser");
    testRunner.setAuthenticationPassword("testPassword");
}

function appendFrame(code)
{
    i = document.createElement("iframe"); 
    i.setAttribute("src", "http://127.0.0.1:8000/misc/authentication-redirect-2/resources/auth-then-redirect.py?redirect=" + code); 
    i.setAttribute("onload", "frameLoaded()");
    document.body.appendChild(i);
}

</script>

<body onload="appendFrame('301');">
https://bugs.webkit.org/show_bug.cgi?id=66354<br>
You should load this page at 127.0.0.1:8000 because the test relies on redirects within the 127.0.0.1:8000 security origin.<br>
This test loads a py script which demands http authentication, then uses it to redirect to another script in the same origin that shows what authentication headers were sent with the final request.<br>
It does this once each for HTTP 301, 302, 303, and 307 redirects.<br>
If not running under DRT, enter any credentials when asked.<br>
</body>

