Thu, 15 Jan 2015 15:55:04 +0100
Back out 97036ab72558 which inappropriately compared turds to third parties.
1 <html>
2 <head> <meta charset="utf-8"> </head>
3 <body>
4 <!-- sandbox="allow-same-origin" -->
5 <!-- Content-Security-Policy: default-src 'self' -->
7 <!-- these should be stopped by CSP -->
8 <img src="http://example.org/tests/content/base/test/csp/file_CSP.sjs?testid=img_bad&type=img/png"> </img>
10 <!-- these should load ok -->
11 <img src="/tests/content/base/test/csp/file_CSP.sjs?testid=img_good&type=img/png" />
12 <script src='/tests/content/base/test/csp/file_CSP.sjs?testid=scripta_bad&type=text/javascript'></script>
14 </body>
15 </html>