| OLD | NEW |
| 1 http://localhost:8000/security/XFrameOptions/resources/x-frame-options-multiple-
headers-sameorigin.cgi - willSendRequest <NSURLRequest URL http://localhost:8000
/security/XFrameOptions/resources/x-frame-options-multiple-headers-sameorigin.cg
i, main document URL http://127.0.0.1:8000/security/XFrameOptions/x-frame-option
s-multiple-headers-sameorigin-deny.html, http method GET> redirectResponse (null
) | |
| 2 CONSOLE ERROR: Refused to display 'http://localhost:8000/security/XFrameOptions/
resources/x-frame-options-multiple-headers-sameorigin.cgi' in a frame because it
set 'X-Frame-Options' to 'SAMEORIGIN, SAMEORIGIN'. | 1 CONSOLE ERROR: Refused to display 'http://localhost:8000/security/XFrameOptions/
resources/x-frame-options-multiple-headers-sameorigin.cgi' in a frame because it
set 'X-Frame-Options' to 'SAMEORIGIN, SAMEORIGIN'. |
| 3 http://localhost:8000/security/XFrameOptions/resources/x-frame-options-multiple-
headers-sameorigin.cgi - didFinishLoading | 2 CONSOLE MESSAGE: line 16: PASS: Access to contentWindow.location.href threw an e
xception. |
| 4 CONSOLE MESSAGE: line 17: PASS: Access to contentWindow.location.href threw an e
xception. | |
| 5 The frame below should not load, proving that 'sameorigin, sameorigin' === 'same
origin'. | 3 The frame below should not load, proving that 'sameorigin, sameorigin' === 'same
origin'. |
| 6 | 4 |
| 7 | 5 |
| 8 | 6 |
| 9 -------- | 7 -------- |
| 10 Frame: '<!--framePath //<!--frame0-->-->' | 8 Frame: '<!--framePath //<!--frame0-->-->' |
| 11 -------- | 9 -------- |
| 12 | 10 |
| OLD | NEW |