|
1 <html> |
|
2 <head> <meta charset="utf-8"> </head> |
|
3 <body> |
|
4 <!-- sandbox="allow-same-origin" --> |
|
5 <!-- Content-Security-Policy: default-src 'self' --> |
|
6 |
|
7 <!-- these should be stopped by CSP --> |
|
8 <img src="http://example.org/tests/content/base/test/csp/file_CSP.sjs?testid=img_bad&type=img/png"> </img> |
|
9 |
|
10 <!-- these should load ok --> |
|
11 <img src="/tests/content/base/test/csp/file_CSP.sjs?testid=img_good&type=img/png" /> |
|
12 <script src='/tests/content/base/test/csp/file_CSP.sjs?testid=scripta_bad&type=text/javascript'></script> |
|
13 |
|
14 </body> |
|
15 </html> |