| Index: LayoutTests/http/tests/security/xssAuditor/full-block-script-tag.html
|
| ===================================================================
|
| --- LayoutTests/http/tests/security/xssAuditor/full-block-script-tag.html (revision 143507)
|
| +++ LayoutTests/http/tests/security/xssAuditor/full-block-script-tag.html (working copy)
|
| @@ -9,11 +9,20 @@
|
| testRunner.waitUntilDone();
|
| testRunner.setXSSAuditorEnabled(true);
|
| }
|
| +
|
| +function checkframe()
|
| +{
|
| + try {
|
| + var ref = document.getElementById("frame").contentDocument.referrer;
|
| + alert('Referrer is "' + ref + '"');
|
| + } catch (e) {}
|
| + checkIfFrameLocationMatchesURLAndCallDone('frame', 'about:blank');
|
| +}
|
| </script>
|
| </head>
|
| <body>
|
| <p>There should be no content in the iframe below:</p>
|
| -<iframe id="frame" onload="checkIfFrameLocationMatchesURLAndCallDone('frame', 'about:blank')" src="http://127.0.0.1:8000/security/xssAuditor/resources/echo-intertag.pl?enable-full-block=1&q=<script>alert(String.fromCharCode(0x58,0x53,0x53))</script>">
|
| +<iframe id="frame" onload="checkframe()" src="http://localhost:8000/security/xssAuditor/resources/echo-intertag.pl?enable-full-block=1&q=<script>alert(String.fromCharCode(0x58,0x53,0x53))</script>">
|
| </iframe>
|
| </body>
|
| </html>
|
|
|