Thu, 22 Jan 2015 13:21:57 +0100
Incorporate requested changes from Mozilla in review:
https://bugzilla.mozilla.org/show_bug.cgi?id=1123480#c6
1 <html>
2 <head> <meta charset="utf-8"> </head>
3 <body>
4 <!-- sandbox -->
5 <!-- Content-Security-Policy: default-src 'self' -->
7 <!-- these should be stopped by CSP -->
8 <img src="http://example.org/tests/content/base/test/csp/file_CSP.sjs?testid=img2_bad&type=img/png"> </img>
10 <!-- these should load ok -->
11 <img src="/tests/content/base/test/csp/file_CSP.sjs?testid=img2a_good&type=img/png" />
13 </body>
14 </html>