On click, the page enters fullscreen and loads an iframe pointing at a
401 WWW-Authenticate endpoint on this origin. Use this to
check how the browser handles a blocking auth prompt from a subframe while
the top-level document owns the fullscreen surface.