<!DOCTYPE HTML> <html> <head> <meta charset="utf-8"> <title>Test for Bug 886262</title> <link rel="stylesheet" type="text/css" href="/tests/SimpleTest/test.css"/> </head> <script> window.addEventListener("message", receiveMessage, false); function receiveMessage(event) { window.parent.parent.postMessage({ok: event.data.ok, desc: "objects containing " + event.data.desc}, "*"); } function doStuff() { try { window.parent.parent.ok_wrapper(false, "an object inside a sandboxed iframe should NOT be same origin with the iframe's parent"); } catch (e) { window.parent.parent.postMessage({ok: true, desc: "an object inside a sandboxed iframe is not same origin with the iframe's parent"}, "*"); } } </script> <body onload='doStuff()'> I'm a <object> inside an iframe which is sandboxed with 'allow-scripts allow-forms' <object data="file_iframe_sandbox_a_if15.html"></object> </body> </html>