diff options
author | janekptacijarabaci <janekptacijarabaci@seznam.cz> | 2017-08-25 09:36:20 +0200 |
---|---|---|
committer | wolfbeast <mcwerewolf@gmail.com> | 2018-02-22 11:20:38 +0100 |
commit | b4dac5093a75a024643b93aef88758770df73c55 (patch) | |
tree | 52b65bf6c091687f9e123c65db45a6f9de17fcec /dom/security/test/csp/file_image_nonce.html | |
parent | a06ce3f03b260d59199dba7e01ea8afb3de1ef59 (diff) | |
download | UXP-b4dac5093a75a024643b93aef88758770df73c55.tar UXP-b4dac5093a75a024643b93aef88758770df73c55.tar.gz UXP-b4dac5093a75a024643b93aef88758770df73c55.tar.lz UXP-b4dac5093a75a024643b93aef88758770df73c55.tar.xz UXP-b4dac5093a75a024643b93aef88758770df73c55.zip |
CSP: Ignore nonces on <img> per spec
Diffstat (limited to 'dom/security/test/csp/file_image_nonce.html')
-rw-r--r-- | dom/security/test/csp/file_image_nonce.html | 39 |
1 files changed, 39 insertions, 0 deletions
diff --git a/dom/security/test/csp/file_image_nonce.html b/dom/security/test/csp/file_image_nonce.html new file mode 100644 index 000000000..5d57bb837 --- /dev/null +++ b/dom/security/test/csp/file_image_nonce.html @@ -0,0 +1,39 @@ +<!DOCTYPE HTML> +<html> + <head> + <meta charset='utf-8'> + <title>Bug 1355801: Nonce should not apply to images</title> + </head> +<body> + +<img id='matchingNonce' src='http://mochi.test:8888/tests/image/test/mochitest/blue.png?a' nonce='abc'></img> +<img id='nonMatchingNonce' src='http://mochi.test:8888/tests/image/test/mochitest/blue.png?b' nonce='bca'></img> +<img id='noNonce' src='http://mochi.test:8888/tests/image/test/mochitest/blue.png?c'></img> + +<script type='application/javascript'> + var matchingNonce = document.getElementById('matchingNonce'); + matchingNonce.onload = function(e) { + window.parent.postMessage({result: 'img-with-matching-nonce-loaded'}, '*'); + }; + matchingNonce.onerror = function(e) { + window.parent.postMessage({result: 'img-with-matching-nonce-blocked'}, '*'); + } + + var nonMatchingNonce = document.getElementById('nonMatchingNonce'); + nonMatchingNonce.onload = function(e) { + window.parent.postMessage({result: 'img-with_non-matching-nonce-loaded'}, '*'); + }; + nonMatchingNonce.onerror = function(e) { + window.parent.postMessage({result: 'img-with_non-matching-nonce-blocked'}, '*'); + } + + var noNonce = document.getElementById('noNonce'); + noNonce.onload = function(e) { + window.parent.postMessage({result: 'img-without-nonce-loaded'}, '*'); + }; + noNonce.onerror = function(e) { + window.parent.postMessage({result: 'img-without-nonce-blocked'}, '*'); + } +</script> +</body> +</html> |