blob: ccc2011593d4cef7ff94104462e4c7e0867fc0a8 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
|
<!DOCTYPE html>
<html>
<head>
<meta charset="utf-8">
<title>Test 911547</title>
</head>
<body>
<!--
this element gets modified by an injected script;
that script should be blocked by CSP.
Inline scripts can modify it, but not data uris.
-->
<input type="text" id="test_id" value="ok">
<a id="test_data_link" href="data:text/html;charset=utf-8,<input type='text' id='test_id2' value='ok'/> <script>document.getElementById('test_id2').value = 'fail';</script>">Test Link</a>
</body>
</html>
|