summaryrefslogtreecommitdiffstats
path: root/testing/web-platform/tests/content-security-policy/blink-contrib/eval-blocked-in-about-blank-iframe.sub.html
blob: 449f9d1927b7ff8db250356041ed087c0aba94d4 (plain)
1
2
3
4
5
6
7
8
9
10

<iframe src="about:blank"></iframe>
Eval should be blocked in the iframe, but inline script should be allowed.
<script>
    window.onload = function() {
        frames[0].log("<script>alert_assert(/PASS/); eval('alert_assert(/FAIL/);');<\/script>");
        frames[0].document.close();
    }

</script>