browser/components/sessionstore/test/browser_911547_sample.html

Thu, 15 Jan 2015 15:59:08 +0100

author
Michael Schloh von Bennewitz <michael@schloh.com>
date
Thu, 15 Jan 2015 15:59:08 +0100
branch
TOR_BUG_9701
changeset 10
ac0c01689b40
permissions
-rw-r--r--

Implement a real Private Browsing Mode condition by changing the API/ABI;
This solves Tor bug #9701, complying with disk avoidance documented in
https://www.torproject.org/projects/torbrowser/design/#disk-avoidance.

     1 <!DOCTYPE html>
     2 <html>
     3   <head>
     4     <title>Test 911547</title>
     5   </head>
     6 <body>
     8   <!--
     9    this element gets modified by an injected script;
    10    that script should be blocked by CSP.
    11    Inline scripts can modify it, but not data uris.
    12   -->
    13   <input type="text" id="test_id" value="ok">
    15   <a id="test_data_link" href="data:text/html,<input type='text' id='test_id2' value='ok'/> <script>document.getElementById('test_id2').value = 'fail';</script>">Test Link</a>
    17 </body>
    18 </html>

mercurial