Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(243)

Side by Side Diff: content/test/data/frame-src-self-and-b.html

Issue 1957783002: Replicate Content-Security-Policy into remote frame proxies. (Closed) Base URL: https://chromium.googlesource.com/chromium/src.git@master
Patch Set: Fixing CSP inheritance for srcdoc. Created 4 years, 7 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch
OLDNEW
(Empty)
1 <!DOCTYPE html>
2 <html>
3 <head>
4 <title>This page should only allow subframes from the same origin or b.com</titl e>
5 </head>
6 <body>
7 This page should only allow subframes from the same origin or from b.com,
8 because its CSP headers specify frame-src 'self' and 'b.com'.
9 <iframe src="/cross-site/b.com/title2.html"></iframe>
10 <iframe srcdoc="
11 &lt;html&gt;
alexmos 2016/05/16 16:17:03 Looking at some other test files with srcdoc ifram
Łukasz Anforowicz 2016/05/16 19:44:45 Oh, indeed - I assumed that I need to escape, but
12 &lt;head&gt;
13 &lt;title&gt;subtitle1&lt;/title&gt;
14 &lt;/head&gt;
15 &lt;body&gt;
16 &lt;iframe src=&quot;/cross-site/b.com/title2.html&quot;&gt;&lt;/iframe&gt ;
17 &lt;/body&gt;
18 &lt;/html&gt;"></iframe>
19 </body>
20 </html>
21
OLDNEW

Powered by Google App Engine
This is Rietveld 408576698