Sat, 03 Jan 2015 20:18:00 +0100
Conditionally enable double key logic according to:
private browsing mode or privacy.thirdparty.isolate preference and
implement in GetCookieStringCommon and FindCookie where it counts...
With some reservations of how to convince FindCookie users to test
condition and pass a nullptr when disabling double key logic.
1 <html>
2 <head> <meta charset="utf-8"> </head>
3 <body>
4 <!-- sandbox="allow-same-origin" -->
5 <!-- Content-Security-Policy: default-src 'self' -->
7 <!-- these should be stopped by CSP -->
8 <img src="http://example.org/tests/content/base/test/csp/file_CSP.sjs?testid=img_bad&type=img/png"> </img>
10 <!-- these should load ok -->
11 <img src="/tests/content/base/test/csp/file_CSP.sjs?testid=img_good&type=img/png" />
12 <script src='/tests/content/base/test/csp/file_CSP.sjs?testid=scripta_bad&type=text/javascript'></script>
14 </body>
15 </html>