-1:000000000000 | 0:28df0f72cbf6 |
---|---|
1 <!DOCTYPE html> | |
2 <html> | |
3 <head> | |
4 <title>Test 911547</title> | |
5 </head> | |
6 <body> | |
7 | |
8 <!-- | |
9 this element gets modified by an injected script; | |
10 that script should be blocked by CSP. | |
11 Inline scripts can modify it, but not data uris. | |
12 --> | |
13 <input type="text" id="test_id" value="ok"> | |
14 | |
15 <a id="test_data_link" href="data:text/html,<input type='text' id='test_id2' value='ok'/> <script>document.getElementById('test_id2').value = 'fail';</script>">Test Link</a> | |
16 | |
17 </body> | |
18 </html> |