Index: third_party/WebKit/LayoutTests/http/tests/security/xssAuditor/iframe-onload-in-svg-tag-expected.txt |
diff --git a/third_party/WebKit/LayoutTests/http/tests/security/xssAuditor/iframe-onload-in-svg-tag-expected.txt b/third_party/WebKit/LayoutTests/http/tests/security/xssAuditor/iframe-onload-in-svg-tag-expected.txt |
index 3131baf07e3a79f41ddd8a1aa84e7fab6a451b07..62c497fa7c17f189c8c43e90cbb9c143518b5940 100644 |
--- a/third_party/WebKit/LayoutTests/http/tests/security/xssAuditor/iframe-onload-in-svg-tag-expected.txt |
+++ b/third_party/WebKit/LayoutTests/http/tests/security/xssAuditor/iframe-onload-in-svg-tag-expected.txt |
@@ -1,2 +1,2 @@ |
-CONSOLE ERROR: line 4: The XSS Auditor refused to execute a script in 'http://localhost:8000/security/xssAuditor/resources/echo-intertag.pl?q=%3Csvg%3E%3Cscript%3E%3Ciframe%20onload=alert(0)%3E%3C/iframe%3E%3C/script%3E%3C/svg%3E' because its source code was found within the request. The auditor was enabled as the server did not send an 'X-XSS-Protection' header. |
+CONSOLE ERROR: line 4: The XSS Auditor refused to execute a script in 'http://localhost:8000/security/xssAuditor/resources/echo-intertag.pl?q=%3Csvg%3E%3Cscript%3E%3Ciframe%20onload=alert(0)%3E%3C/iframe%3E%3C/script%3E%3C/svg%3E' because its source code was found within the request. The server sent an 'X-XSS-Protection' header requesting this behavior. |
Test that dangerous attributes are still filtered in netsted script contexts. |