Thu, 22 Jan 2015 13:21:57 +0100
Incorporate requested changes from Mozilla in review:
https://bugzilla.mozilla.org/show_bug.cgi?id=1123480#c6
1 <html>
2 <head> <meta charset="utf-8"> </head>
3 <body>
4 <!-- sandbox -->
5 <!-- Content-Security-Policy: default-src 'none' -->
7 <!-- these should be stopped by CSP -->
8 <img src="http://example.org/tests/content/base/test/csp/file_CSP.sjs?testid=img3_bad&type=img/png"> </img>
9 <img src="/tests/content/base/test/csp/file_CSP.sjs?testid=img3a_bad&type=img/png" />
11 </body>
12 </html>