Sat, 03 Jan 2015 20:18:00 +0100
Conditionally enable double key logic according to:
private browsing mode or privacy.thirdparty.isolate preference and
implement in GetCookieStringCommon and FindCookie where it counts...
With some reservations of how to convince FindCookie users to test
condition and pass a nullptr when disabling double key logic.
michael@0 | 1 | <!DOCTYPE HTML> |
michael@0 | 2 | <html> |
michael@0 | 3 | <!-- |
michael@0 | 4 | https://bugzilla.mozilla.org/show_bug.cgi?id=423375 |
michael@0 | 5 | --> |
michael@0 | 6 | <head> |
michael@0 | 7 | <title>Test for Bug 423375</title> |
michael@0 | 8 | <script type="text/javascript" src="/tests/SimpleTest/SimpleTest.js"></script> |
michael@0 | 9 | <link rel="stylesheet" type="text/css" href="/tests/SimpleTest/test.css" /> |
michael@0 | 10 | </head> |
michael@0 | 11 | <body> |
michael@0 | 12 | <a target="_blank" href="https://bugzilla.mozilla.org/show_bug.cgi?id=423375">Mozilla Bug 423375</a> |
michael@0 | 13 | <p id="display"></p> |
michael@0 | 14 | <div id="content" style="display: none"> |
michael@0 | 15 | <iframe id="load-frame"></iframe> |
michael@0 | 16 | </div> |
michael@0 | 17 | <pre id="test"> |
michael@0 | 18 | <script class="testbody" type="text/javascript"> |
michael@0 | 19 | |
michael@0 | 20 | /** |
michael@0 | 21 | ** Test for Bug 423375 |
michael@0 | 22 | ** (content shouldn't be able to load chrome: or resource:) |
michael@0 | 23 | **/ |
michael@0 | 24 | function tryLoad(url) |
michael@0 | 25 | { |
michael@0 | 26 | try { |
michael@0 | 27 | window.frames[0].location = url; |
michael@0 | 28 | return "loaded"; |
michael@0 | 29 | } catch (e if /Access.*denied/.test(String(e))) { |
michael@0 | 30 | return "denied"; |
michael@0 | 31 | } catch (e) { |
michael@0 | 32 | return "unexpected: " + e; |
michael@0 | 33 | } |
michael@0 | 34 | } |
michael@0 | 35 | |
michael@0 | 36 | is(tryLoad("chrome://global/content/mozilla.xhtml"), "denied", |
michael@0 | 37 | "content should have been prevented from loading chrome: URL"); |
michael@0 | 38 | is(tryLoad("resource://gre-resources/html.css"), "denied", |
michael@0 | 39 | "content should have been prevented from loading resource: URL"); |
michael@0 | 40 | </script> |
michael@0 | 41 | </pre> |
michael@0 | 42 | </body> |
michael@0 | 43 | </html> |
michael@0 | 44 |