| OLD | NEW | 
| (Empty) |  | 
 |   1 <!DOCTYPE html> | 
 |   2 <html> | 
 |   3  | 
 |   4 <head> | 
 |   5     <!-- Programmatically converted from a WebKit Reftest, please forgive result
    ing idiosyncracies.--> | 
 |   6     <title>blob-urls-do-not-match-self</title> | 
 |   7     <script src="/resources/testharness.js"></script> | 
 |   8     <script src="/resources/testharnessreport.js"></script> | 
 |   9     <script src="../support/logTest.sub.js?logs=[]"></script> | 
 |  10     <script src="../support/alertAssert.sub.js?alerts=[]"></script> | 
 |  11     <!-- enforcing policy: | 
 |  12 script-src 'self' 'unsafe-inline'; connect-src 'self'; child-src 'self'; | 
 |  13 --> | 
 |  14 </head> | 
 |  15  | 
 |  16 <body> | 
 |  17     <p> | 
 |  18         blob: URLs are same-origin with the page in which they were created, but
     explicitly do not match the 'self' or '*' source in CSP directives be
    cause they are more akin to 'unsafe-inline' content. | 
 |  19     </p> | 
 |  20     <script> | 
 |  21         function fail() { | 
 |  22             alert_assert("FAIL!"); | 
 |  23         } | 
 |  24         var b = new Blob(['fail();'], { | 
 |  25             type: 'application/javascript' | 
 |  26         }); | 
 |  27         var script = document.createElement('script'); | 
 |  28         script.src = URL.createObjectURL(b); | 
 |  29         document.body.appendChild(script); | 
 |  30  | 
 |  31     </script> | 
 |  32     <div id="log"></div> | 
 |  33     <script async defer src="../support/checkReport.sub.js?reportExists=true&
    ;reportField=violated-directive&reportValue=script-src%20'self'%20
    'unsafe-inline'%20''"></script> | 
 |  34 </body> | 
 |  35  | 
 |  36 </html> | 
| OLD | NEW |