diff options
Diffstat (limited to 'components/script')
-rw-r--r-- | components/script/dom/webidls/XMLHttpRequest.webidl | 1 | ||||
-rw-r--r-- | components/script/dom/xmlhttprequest.rs | 17 |
2 files changed, 16 insertions, 2 deletions
diff --git a/components/script/dom/webidls/XMLHttpRequest.webidl b/components/script/dom/webidls/XMLHttpRequest.webidl index ba100ca23ad..6066ba9c17b 100644 --- a/components/script/dom/webidls/XMLHttpRequest.webidl +++ b/components/script/dom/webidls/XMLHttpRequest.webidl @@ -50,6 +50,7 @@ interface XMLHttpRequest : XMLHttpRequestEventTarget { void setRequestHeader(ByteString name, ByteString value); [SetterThrows] attribute unsigned long timeout; + [SetterThrows] attribute boolean withCredentials; readonly attribute XMLHttpRequestUpload upload; [Throws] diff --git a/components/script/dom/xmlhttprequest.rs b/components/script/dom/xmlhttprequest.rs index 0f6e9551272..961125bf25b 100644 --- a/components/script/dom/xmlhttprequest.rs +++ b/components/script/dom/xmlhttprequest.rs @@ -489,8 +489,21 @@ impl<'a> XMLHttpRequestMethods for JSRef<'a, XMLHttpRequest> { fn WithCredentials(self) -> bool { self.with_credentials.get() } - fn SetWithCredentials(self, with_credentials: bool) { - self.with_credentials.set(with_credentials); + // Spec for SetWithCredentials: https://xhr.spec.whatwg.org/#dom-xmlhttprequest-withcredentials + fn SetWithCredentials(self, with_credentials: bool) -> ErrorResult { + match self.ready_state.get() { + XMLHttpRequestState::HeadersReceived | + XMLHttpRequestState::Loading | + XMLHttpRequestState::XHRDone => Err(InvalidState), + _ if self.send_flag.get() => Err(InvalidState), + _ => match self.global.root() { + GlobalRoot::Window(_) if self.sync.get() => Err(InvalidAccess), + _ => { + self.with_credentials.set(with_credentials); + Ok(()) + }, + }, + } } fn Upload(self) -> Temporary<XMLHttpRequestUpload> { Temporary::new(self.upload) |