Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(14)

Side by Side Diff: third_party/WebKit/LayoutTests/http/tests/security/xss-DENIED-window-open-parent-expected.txt

Issue 2092293002: Block framebusts without a user gesture (Closed) Base URL: https://chromium.googlesource.com/chromium/src.git@master
Patch Set: better flag description Created 4 years, 3 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch
OLDNEW
1 CONSOLE ERROR: line 2: Blocked a frame with origin "http://localhost:8080" from accessing a frame with origin "http://127.0.0.1:8000". Protocols, domains, and p orts must match. 1 CONSOLE ERROR: line 2: Unsafe JavaScript attempt to initiate navigation for fram e with URL 'http://127.0.0.1:8000/security/xss-DENIED-window-open-parent.html' f rom frame with URL 'http://localhost:8080/security/resources/xss-DENIED-window-o pen-parent-attacker.html'. The frame attempting navigation is targeting its top- level window, but is neither same-origin with its target nor is it processing a user gesture. See https://www.chromestatus.com/features/5851021045661696.
2
2 This test passes if there is no alert dialog. 3 This test passes if there is no alert dialog.
3 4
OLDNEW

Powered by Google App Engine
This is Rietveld 408576698