Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(81)

Side by Side Diff: third_party/WebKit/LayoutTests/http/tests/security/contentSecurityPolicy/resources/respond-with-multiple-csp-headers.php

Issue 2526473005: Part 4.1: Is policy list subsumed under subsuming policy? (Closed)
Patch Set: Rebasing on master Created 4 years ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch
OLDNEW
(Empty)
1 <?php
2 $csp = isset($_GET['csp']) ? $_GET['csp'] : null;
3 if ($csp)
4 header('Content-Security-Policy: ' . $csp);
5 $csp2 = isset($_GET['csp2']) ? $_GET['csp2'] : null;
6 if ($csp2)
7 header('Content-Security-Policy: ' . $csp2);
8 $csp_report_only = isset($_GET['csp_report_only']) ? $_GET['csp_report_only' ] : null;
9 if ($csp_report_only)
10 header('Content-Security-Policy-Report-Only: ' . $csp_report_only);
11 $msg = isset($_GET['id']) ? $_GET['id'] : null;
12 ?>
13
14 <!DOCTYPE html>
15 <html>
16 <head>
17 <title>This page enforces embedder's policies</title>
18 <script nonce="123">
19 document.addEventListener("securitypolicyviolation", function(e) {
20 var response = {};
21 response["id"] = "<?php echo $msg; ?>";
22 response["securitypolicyviolation"] = true;
23 response["blockedURI"] = e.blockedURI;
24 response["lineNumber"] = e.lineNumber;
25 window.top.postMessage(response, '*');
26 });
27 </script>
28 </head>
29 <body>
30 Hello World.
31 <iframe src="/cross-site/b.com/title2.html"></iframe>
32 <img src="green250x50.png" />
33 <script nonce="abc">
34 var response = {};
35 response["loaded"] = true;
36 response["id"] = "<?php echo $msg; ?>";
37 window.onload = window.top.postMessage(response, '*');
38 </script>
39 </body>
40 </html>
OLDNEW

Powered by Google App Engine
This is Rietveld 408576698