Porting access-control-response-with-body from LayoutTest to WPT

Bug: 745385
Change-Id: I90461ac5d10414180198df10ca55a05be8ca1d66
Reviewed-on: https://chromium-review.googlesource.com/644830
Commit-Queue: Austin James Ahlstrom <aahlstrom@google.com>
Reviewed-by: Takeshi Yoshino <tyoshino@chromium.org>
Reviewed-by: Yutaka Hirano <yhirano@chromium.org>
Cr-Commit-Position: refs/heads/master@{#500197}
diff --git a/XMLHttpRequest/access-control-response-with-body.htm b/XMLHttpRequest/access-control-response-with-body.htm
new file mode 100644
index 0000000..ab89cef
--- /dev/null
+++ b/XMLHttpRequest/access-control-response-with-body.htm
@@ -0,0 +1,29 @@
+<!DOCTYPE html>
+<html>
+  <head>
+    <title>Tests that XHR doesn't prepend the body from CORS preflight response to the actual response</title>
+    <script src="/resources/testharness.js"></script>
+    <script src="/resources/testharnessreport.js"></script>
+    <script src="/common/get-host-info.sub.js"></script>
+  </head>
+  <body>
+    <script type="text/javascript">
+async_test((test) => {
+  const xhr = new XMLHttpRequest;
+
+  xhr.onerror = test.unreached_func("Unexpected error.");
+
+  xhr.onload = test.step_func_done(() => {
+    assert_equals(xhr.status, 200);
+    assert_equals(xhr.responseText, "PASS");
+  });
+
+  xhr.open("GET", get_host_info().HTTP_REMOTE_ORIGIN +
+      "/XMLHttpRequest/resources/access-control-allow-with-body.py");
+  xhr.setRequestHeader("Content-Type", "application/x-www-form-urlencoded");
+  xhr.setRequestHeader("X-Requested-With", "XMLHttpRequest");
+  xhr.send();
+});
+    </script>
+  </body>
+</html>
diff --git a/XMLHttpRequest/resources/access-control-allow-with-body.py b/XMLHttpRequest/resources/access-control-allow-with-body.py
new file mode 100644
index 0000000..2213435
--- /dev/null
+++ b/XMLHttpRequest/resources/access-control-allow-with-body.py
@@ -0,0 +1,15 @@
+def main(request, response):
+    headers = {
+            "Cache-Control": "no-store",
+            "Access-Control-Allow-Headers": "X-Requested-With",
+            "Access-Control-Max-Age": 0,
+            "Access-Control-Allow-Origin": "*",
+            "Access-Control-Allow-Methods": "*",
+            "Vary": "Accept-Encoding",
+            "Content-Type": "text/plain"
+    }
+
+    for (name, value) in headers.items():
+        response.headers.set(name, value)
+
+    response.content = "PASS"