Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(239)

Side by Side Diff: LayoutTests/http/tests/security/xssAuditor/viewsource-onmouseover-expected.txt

Issue 420603003: Better distinguish between blocked and empty pages in XSS filter tests. (Closed) Base URL: svn://svn.chromium.org/blink/trunk
Patch Set: Remove stray file. Created 6 years, 5 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch | Annotate | Revision Log
OLDNEW
1 <!DOCTYPE html><html><head></head><body><iframe id="x" name="x" src="/security/x ssAuditor/resources/echo-intertag.pl?q=%3cdiv%20onmouseover=%22alert(/xss/)%22%% 3e%3c/div%3e"></iframe> 1 <!DOCTYPE html><html><head></head><body><iframe id="x" name="x" src="/security/x ssAuditor/resources/echo-intertag.pl?q=%3cdiv%20onmouseover=%22alert(/xss/)%22%% 3e%3c/div%3e"></iframe>
2 <script> 2 <script>
3 var frame = document.getElementById('x'); 3 var frame = document.getElementById('x');
4 if (window.testRunner) { 4 if (window.testRunner) {
5 testRunner.waitUntilDone(); 5 testRunner.waitUntilDone();
6 testRunner.setXSSAuditorEnabled(true); 6 testRunner.setXSSAuditorEnabled(true);
7 testRunner.dumpAsMarkup(); 7 testRunner.dumpAsMarkup();
8 testRunner.dumpChildFramesAsMarkup(); 8 testRunner.dumpChildFramesAsMarkup();
9 testRunner.setViewSourceForFrame('x', true); 9 testRunner.setViewSourceForFrame('x', true);
10 frame.onload = testRunner.notifyDone.bind(testRunner); 10 frame.onload = testRunner.notifyDone.bind(testRunner);
11 } 11 }
12 frame.src = '/security/xssAuditor/resources/echo-intertag.pl?q=%3cdiv%20onmouseo ver=%22alert(/xss/)%22%%3e%3c/div%3e'; 12 frame.src = '/security/xssAuditor/resources/echo-intertag.pl?q=%3cdiv%20onmouseo ver=%22alert(/xss/)%22%%3e%3c/div%3e';
13 </script> 13 </script>
14 <p>This test passes if the iframe is rendered in view-source mode and the div wi th the 14 <p>This test passes if the iframe is rendered in view-source mode and the div wi th the
15 onmouseover handler is in a highlighted span.</p> 15 onmouseover handler is in a highlighted span.</p>
16 16
17 </body></html> 17 </body></html>
18 18
19 -------- 19 --------
20 Frame: 'x' 20 Frame: 'x'
21 -------- 21 --------
22 <html><head></head><body><div class="line-gutter-backdrop"></div><table><tbody>< tr><td class="line-number" value="1"></td><td class="line-content"><span class=" html-doctype">&lt;!DOCTYPE html&gt;</span></td></tr><tr><td class="line-number" value="2"></td><td class="line-content"><span class="html-tag">&lt;html&gt;</spa n></td></tr><tr><td class="line-number" value="3"></td><td class="line-content"> <span class="html-tag">&lt;body&gt;</span></td></tr><tr><td class="line-number" value="4"></td><td class="line-content"><span class="highlight" title="Token con tains a reflected XSS vector"><span class="html-tag">&lt;div <span class="html-a ttribute-name">onmouseover</span>="<span class="html-attribute-value">alert(/xss /)</span>"<span class="html-attribute-name">%</span>&gt;</span></span><span clas s="html-tag">&lt;/div&gt;</span><span class="html-tag">&lt;/body&gt;</span></td> </tr><tr><td class="line-number" value="5"></td><td class="line-content"><span c lass="html-tag">&lt;/html&gt;</span></td></tr><tr><td class="line-number" value= "6"></td><td class="line-content"><span class="html-end-of-file"></span></td></t r></tbody></table></body></html> 22 <html><head></head><body><div class="line-gutter-backdrop"></div><table><tbody>< tr><td class="line-number" value="1"></td><td class="line-content"><span class=" html-doctype">&lt;!DOCTYPE html&gt;</span></td></tr><tr><td class="line-number" value="2"></td><td class="line-content"><span class="html-tag">&lt;html&gt;</spa n></td></tr><tr><td class="line-number" value="3"></td><td class="line-content"> <span class="html-tag">&lt;body&gt;</span></td></tr><tr><td class="line-number" value="4"></td><td class="line-content"><span class="highlight" title="Token con tains a reflected XSS vector"><span class="html-tag">&lt;div <span class="html-a ttribute-name">onmouseover</span>="<span class="html-attribute-value">alert(/xss /)</span>"<span class="html-attribute-name">%</span>&gt;</span></span><span clas s="html-tag">&lt;/div&gt;</span>Page rendered here.</td></tr><tr><td class="line -number" value="5"></td><td class="line-content"><span class="html-tag">&lt;/bod y&gt;</span></td></tr><tr><td class="line-number" value="6"></td><td class="line -content"><span class="html-tag">&lt;/html&gt;</span></td></tr><tr><td class="li ne-number" value="7"></td><td class="line-content"><span class="html-end-of-file "></span></td></tr></tbody></table></body></html>
OLDNEW

Powered by Google App Engine
This is Rietveld 408576698