Index: LayoutTests/http/tests/security/contentSecurityPolicy/1.1/scriptnonce-ignore-unsafeinline-expected.txt |
diff --git a/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/scriptnonce-ignore-unsafeinline-expected.txt b/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/scriptnonce-ignore-unsafeinline-expected.txt |
new file mode 100644 |
index 0000000000000000000000000000000000000000..8e99347115740875dea83414d18ba1e3200d1cdd |
--- /dev/null |
+++ b/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/scriptnonce-ignore-unsafeinline-expected.txt |
@@ -0,0 +1,5 @@ |
+ALERT: PASS (1/2) |
+ALERT: PASS (2/2) |
+CONSOLE ERROR: line 15: Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'nonce-noncynonce' 'nonce-noncy+/=nonce' 'unsafe-inline'". Note that 'unsafe-inline' is ignored if either a hash or nonce value is present in the source list. |
+ |
+This tests that a valid nonce disables inline JavaScript, even if 'unsafe-inline' is present. |