Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(109)

Side by Side Diff: third_party/WebKit/LayoutTests/http/tests/security/contentSecurityPolicy/resources/respond-with-allow-csp-from-header.php

Issue 2404373003: Experimental Feature: Allow-CSP-From header (Closed)
Patch Set: Better format of ContentSecurityPolicyTest.ShouldEnforceEmbeddersPolicy Created 4 years, 2 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch
OLDNEW
(Empty)
1 <?php
2 $allow_csp_from = isset($_GET['allow_csp_from']) ? $_GET['allow_csp_from'] : null;
3 if ($allow_csp_from)
4 header('Allow-CSP-From: ' . $allow_csp_from);
5 $csp = isset($_GET['csp']) ? $_GET['csp'] : null;
6 if ($csp)
7 header('Content-Security-Policy: ' . $csp);
8 $msg = isset($_GET['id']) ? $_GET['id'] : null;
9 ?>
10
11 <!DOCTYPE html>
12 <html>
13 <head>
14 <title>This page enforces embedder's policies</title>
15 <script nonce="123">
16 document.addEventListener("securitypolicyviolation", function(e) {
17 var response = {};
18 response["id"] = "<?php echo $msg; ?>";
19 response["securitypolicyviolation"] = true;
20 response["blockedURI"] = e.blockedURI;
21 response["lineNumber"] = e.lineNumber;
22 window.top.postMessage(response, '*');
23 });
24 </script>
25 </head>
26 <body>
27 Hello World.
28 <iframe src="/cross-site/b.com/title2.html"></iframe>
29 <img src="green250x50.png" />
30 <script nonce="abc">
31 var response = {};
32 response["loaded"] = true;
33 response["id"] = "<?php echo $msg; ?>";
34 window.onload = window.top.postMessage(response, '*');
35 </script>
36 </body>
37 </html>
OLDNEW

Powered by Google App Engine
This is Rietveld 408576698