Index: LayoutTests/http/tests/security/contentSecurityPolicy/block-mixed-content-hides-warning-expected.txt |
diff --git a/LayoutTests/http/tests/security/contentSecurityPolicy/block-mixed-content-hides-warning-expected.txt b/LayoutTests/http/tests/security/contentSecurityPolicy/block-mixed-content-hides-warning-expected.txt |
index 8dbd454400529ab51a53d38236ddf3773abb8f80..f9e078076bfa80d59669d2dd6f8f1f58c8784fd8 100644 |
--- a/LayoutTests/http/tests/security/contentSecurityPolicy/block-mixed-content-hides-warning-expected.txt |
+++ b/LayoutTests/http/tests/security/contentSecurityPolicy/block-mixed-content-hides-warning-expected.txt |
@@ -1,3 +1,5 @@ |
+CONSOLE WARNING: line 1: The page at 'https://127.0.0.1:8443/security/contentSecurityPolicy/resources/mixed-content-with-csp.html' was loaded over HTTPS, but ran insecure content from 'http://127.0.0.1:8080/security/contentSecurityPolicy/resources/alert-fail.js': this content should also be loaded over HTTPS. |
+ |
CONSOLE ERROR: Refused to load the script 'http://127.0.0.1:8080/security/contentSecurityPolicy/resources/alert-fail.js' because it violates the following Content Security Policy directive: "default-src 'self'". Note that 'script-src' was not explicitly set, so 'default-src' is used as a fallback. |
This page should neither alert "FAIL" nor generate any mixed content warnings in the console. |