| OLD | NEW | 
 | (Empty) | 
|   1 <!DOCTYPE HTML> |  | 
|   2 <html> |  | 
|   3 <head> |  | 
|   4     <title>img element src attribute must match src list.</title> |  | 
|   5     <script src='/resources/testharness.js'></script> |  | 
|   6     <script src='/resources/testharnessreport.js'></script> |  | 
|   7 </head> |  | 
|   8 <body> |  | 
|   9     <h1>img element src attribute must match src list.</h1> |  | 
|  10     <p> |  | 
|  11     <div id='log'></div> |  | 
|  12  |  | 
|  13     <script type="text/javascript"> |  | 
|  14       var t1 = async_test("img-src for relative path should load."); |  | 
|  15       var t2 = async_test("img-src from unapproved domains should not load"); |  | 
|  16       var t3 = async_test("img-src from approved domains should load"); |  | 
|  17     </script> |  | 
|  18  |  | 
|  19     <img src='/content-security-policy/support/pass.png' |  | 
|  20     onerror='t1.step(function() { assert_unreached("The img should have loaded."
    ); t1.done() });' |  | 
|  21     onload='t1.done();'> |  | 
|  22  |  | 
|  23     <img src='http://www1.web-platform.test/content-security-policy/support/fail
    .png' |  | 
|  24     onerror='t2.done();' |  | 
|  25     onload='t2.step(function() { assert_unreached("Image from unapproved domain 
    was loaded."); t2.done()} );'> |  | 
|  26  |  | 
|  27     <div id='t3'></div> |  | 
|  28  |  | 
|  29     <script> |  | 
|  30       var t3img = document.createElement('img'); |  | 
|  31       t3img.onerror = function() {t3.step(function() { assert_unreached(); t3.do
    ne();})} |  | 
|  32       t3img.onload = function() {t3.done();} |  | 
|  33       t3img.src = location.protocol + '//www.' + location.hostname + ':' + locat
    ion.port + |  | 
|  34            '/content-security-policy/support/pass.png'; |  | 
|  35       var t3div = document.getElementById('t3'); |  | 
|  36       t3div.appendChild(t3img); |  | 
|  37  |  | 
|  38       var report = document.createElement('script'); |  | 
|  39       report.src = '../support/checkReport.sub.js?reportField=violated-directive
    &reportValue=img-src%20%27self%27%20www.' + location.hostname + (location.port ?
     ':' + location.port : ''); |  | 
|  40       t3div.appendChild(report); |  | 
|  41  |  | 
|  42     </script> |  | 
|  43  |  | 
|  44  |  | 
|  45 </body> |  | 
|  46 </html> |  | 
| OLD | NEW |