OLD | NEW |
1 <script> | 1 <script> |
2 if (window.testRunner) | 2 if (window.testRunner) |
3 testRunner.dumpAsText(); | 3 testRunner.dumpAsText(); |
4 </script> | 4 </script> |
5 <meta http-equiv="Content-Security-Policy" content="script-src 'unsafe-inline'"> | 5 <meta http-equiv="Content-Security-Policy" content="script-src 'unsafe-inline'"> |
6 <iframe src="about:blank"></iframe> | 6 <iframe src="about:blank"></iframe> |
7 Eval should be blocked in the iframe, but inline script should be allowed. | 7 Eval should be blocked in the iframe, but inline script should be allowed. |
8 <script> | 8 <script> |
9 window.onload = function() { | 9 window.onload = function() { |
10 frames[0].document.write("<script>alert(/PASS/); eval('alert(/FAIL/);');<\/s
cript>"); | 10 frames[0].document.write("<script>alert(/PASS/); eval('alert(/FAIL/);');<\/s
cript>"); |
| 11 frames[0].document.close(); |
11 } | 12 } |
12 </script> | 13 </script> |
OLD | NEW |