1 CONSOLE ERROR: line 4: The XSS Auditor refused to execute a script in 'http://12
7.0.0.1:8000/security/xssAuditor/resources/echo-intertag.pl?q=%3Cscript%3Ealert(
/XSS/)%3C/script%3E%3Cp%3EIf%20you%20see%20this%20message%20and%20no%20JavaScrip
t%20alert()%20then%20the%20test%20PASSED.%3C/p%3E' because its source code was f
ound within the request. The auditor was enabled as the server sent neither an '
X-XSS-Protection' nor 'Content-Security-Policy' header.
1 CONSOLE ERROR: line 4: The XSS Auditor refused to execute a script in 'http://12
7.0.0.1:8000/security/xssAuditor/resources/echo-intertag.pl?q=%3Cscript%3Ealert(
/XSS/)%3C/script%3E%3Cp%3EIf%20you%20see%20this%20message%20and%20no%20JavaScrip
t%20alert()%20then%20the%20test%20PASSED.%3C/p%3E' because its source code was f
ound within the request. The auditor was enabled as the server sent neither an '
X-XSS-Protection' nor 'Content-Security-Policy' header.
2 This tests that the header X-XSS-Protection is not inherited by the iframe below
:
2 This tests that the header X-XSS-Protection is not inherited by the iframe below
:
3
3
4
4
5
5
6 --------
6 --------
7 Frame: 'frame'
7 Frame: 'frame'
8 --------
8 --------
9 If you see this message and no JavaScript alert() then the test PASSED.
9 If you see this message and no JavaScript alert() then the test PASSED.
Issue 420603003: Better distinguish between blocked and empty pages in XSS filter tests.
(Closed)
Created 6 years, 5 months ago by Tom Sepez
Modified 6 years, 5 months ago
Reviewers: Mike West
Base URL: svn://svn.chromium.org/blink/trunk
Comments: 0