Changeset 279838 in webkit
- Timestamp:
- Jul 12, 2021, 10:59:36 AM (5 years ago)
- Location:
- trunk/LayoutTests
- Files:
-
- 816 added
- 27 deleted
- 269 edited
- 1 copied
- 8 moved
-
ChangeLog (modified) (1 diff)
-
TestExpectations (modified) (7 diffs)
-
imported/w3c/ChangeLog (modified) (1 diff)
-
imported/w3c/resources/import-expectations.json (modified) (1 diff)
-
imported/w3c/resources/resource-files.json (modified) (3 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/README.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/base-uri/report-uri-does-not-respect-base-uri.sub.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/blob/blob-urls-match-blob.sub.html (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/blob/self-doesnt-match-blob.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/blob/star-doesnt-match-blob.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/child-src/child-src-about-blank-allowed-by-default.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/child-src/child-src-about-blank-allowed-by-scheme.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/child-src/child-src-allowed.sub.html (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/child-src/child-src-blocked.sub.html (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/child-src/child-src-conflicting-frame-src.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/child-src/child-src-cross-origin-load.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/child-src/child-src-redirect-blocked.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/connect-src/shared-worker-connect-src-allowed.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/connect-src/shared-worker-connect-src-blocked.sub.html (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/connect-src/worker-connect-src-allowed.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/connect-src/worker-connect-src-blocked.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/connect-src/worker-from-guid.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/META.yml (added)
-
imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/allow_csp_from-header.html (modified) (3 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/change-csp-attribute-and-history-navigation.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/required-csp-header-cascade.html (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/required_csp-header-crlf.html (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/required_csp-header.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-general.html (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-hashes.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-host_sources-hosts.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-host_sources-paths.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-host_sources-ports.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-host_sources-protocols.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-none.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-self.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-source_list-wildcards.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-strict_dynamic.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-unsafe_eval.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-unsafe_inline.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/support/echo-allow-csp-from.py (modified) (3 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/support/echo-policy-multiple.py (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/support/echo-required-csp.py (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/support/embed-img-and-message-top.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/support/testharness-helper.sub.js (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/support/w3c-import.log (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/w3c-import.log (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/form-action/form-action-src-redirect-blocked.sub-expected.txt (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/form-action/form-action-src-redirect-blocked.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-same-none-block-expected.txt (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-same-self-block-expected.txt (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-same-star-allow.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/frame-ancestors-nested-same-in-same-self-allow-expected.txt (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/frame-ancestors-none-block-expected.txt (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/frame-ancestors-none-block.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/report-blocked-frame.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/report-only-frame.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/support/frame-in-frame.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-about-blank-allowed-by-default.sub.html (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-about-blank-allowed-by-scheme.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-allowed.sub.html (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-blocked.sub.html (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-cross-origin-load.sub.html (modified) (3 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-same-document.sub.html (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-same-document.sub.html.headers (moved) (moved from trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-same-document.html.headers )
-
imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-sandboxed-allowed-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-sandboxed-allowed.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-sandboxed-allowed.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-self-unique-origin.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/frame-src/w3c-import.log (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/gen (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/script-tag.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/script-tag.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/script-tag.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/script-tag.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/script-tag.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/script-tag.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-classic.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-classic.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-classic.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-classic.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-classic.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-classic.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-import-data.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-import-data.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-import-data.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-import-data.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-import.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-import.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-import.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-import.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-import.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-import.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-module.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-module.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-module.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-module.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-module.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-module.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/w3c-import.log (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-classic.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-classic.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-classic.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-classic.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-classic.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-classic.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-import-data.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-import-data.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-import-data.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-import-data.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-import.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-import.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-import.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-import.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-import.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-import.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-module.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-module.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-module.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-module.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-module.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-module.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-animation-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-animation-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-animation-import-data.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-animation.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-animation.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-animation.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-audio-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-audio-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-audio-import-data.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-audio.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-audio.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-audio.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-layout-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-layout-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-layout-import-data.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-layout.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-layout.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-layout.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-paint-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-paint-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-paint-import-data.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-paint.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-paint.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-paint.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/script-tag.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/script-tag.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/script-tag.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/script-tag.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/script-tag.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/script-tag.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-classic.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-classic.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-classic.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-classic.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-classic.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-classic.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-import-data.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-import-data.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-import-data.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-import-data.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-import.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-import.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-import.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-import.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-import.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-import.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-module.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-module.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-module.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-module.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-module.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-module.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/w3c-import.log (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-classic.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-classic.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-classic.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-classic.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-classic.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-classic.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-import-data.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-import-data.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-import-data.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-import-data.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-import.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-import.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-import.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-import.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-import.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-import.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-module.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-module.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-module.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-module.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-module.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-module.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-animation-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-animation-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-animation-import-data.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-animation.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-animation.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-animation.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-audio-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-audio-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-audio-import-data.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-audio.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-audio.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-audio.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-layout-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-layout-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-layout-import-data.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-layout.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-layout.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-layout.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-paint-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-paint-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-paint-import-data.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-paint.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-paint.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-paint.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/script-tag.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/script-tag.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/script-tag.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/script-tag.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/script-tag.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/script-tag.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-classic.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-classic.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-classic.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-classic.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-classic.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-classic.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-import-data.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-import-data.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-import-data.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-import-data.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-import.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-import.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-import.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-import.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-import.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-import.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-module.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-module.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-module.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-module.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-module.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-module.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/w3c-import.log (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-classic.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-classic.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-classic.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-classic.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-classic.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-classic.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-import-data.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-import-data.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-import-data.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-import-data.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-import.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-import.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-import.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-import.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-import.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-import.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-module.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-module.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-module.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-module.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-module.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-module.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-animation-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-animation-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-animation-import-data.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-animation.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-animation.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-animation.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-audio-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-audio-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-audio-import-data.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-audio.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-audio.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-audio.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-layout-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-layout-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-layout-import-data.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-layout.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-layout.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-layout.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-paint-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-paint-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-paint-import-data.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-paint.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-paint.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-paint.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/script-tag.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/script-tag.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/script-tag.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/script-tag.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/script-tag.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/script-tag.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-classic.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-classic.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-classic.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-classic.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-classic.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-classic.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-import-data.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-import-data.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-import-data.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-import-data.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-import.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-import.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-import.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-import.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-import.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-import.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-module.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-module.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-module.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-module.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-module.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-module.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/w3c-import.log (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-classic.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-classic.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-classic.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-classic.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-classic.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-classic.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-import-data.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-import-data.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-import-data.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-import-data.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-import.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-import.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-import.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-import.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-import.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-import.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-module.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-module.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-module.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-module.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-module.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-module.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-animation-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-animation-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-animation-import-data.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-animation.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-animation.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-animation.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-audio-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-audio-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-audio-import-data.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-audio.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-audio.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-audio.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-layout-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-layout-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-layout-import-data.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-layout.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-layout.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-layout.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-paint-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-paint-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-paint-import-data.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-paint.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-paint.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-paint.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/script-tag.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/script-tag.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/script-tag.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/script-tag.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/script-tag.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/script-tag.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-classic.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-classic.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-classic.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-classic.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-classic.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-classic.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-import-data.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-import-data.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-import-data.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-import-data.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-import.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-import.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-import.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-import.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-import.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-import.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-module.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-module.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-module.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-module.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-module.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-module.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/w3c-import.log (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-classic.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-classic.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-classic.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-classic.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-classic.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-classic.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-import-data.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-import-data.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-import-data.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-import-data.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-import.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-import.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-import.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-import.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-import.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-import.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-module.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-module.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-module.http.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-module.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-module.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-module.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-animation-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-animation-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-animation-import-data.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-animation.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-animation.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-animation.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-audio-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-audio-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-audio-import-data.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-audio.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-audio.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-audio.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-layout-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-layout-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-layout-import-data.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-layout.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-layout.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-layout.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-paint-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-paint-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-paint-import-data.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-paint.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-paint.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-paint.https.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/script-tag.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/script-tag.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/script-tag.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/script-tag.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-classic.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-classic.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-classic.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-classic.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-import-data.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-import-data.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-import.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-import.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-import.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-import.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-module.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-module.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-module.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-module.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/w3c-import.log (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-classic.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-classic.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-classic.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-classic.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-import-data.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-import-data.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-import.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-import.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-import.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-import.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-module.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-module.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-module.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-module.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-animation-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-animation-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-animation.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-animation.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-audio-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-audio-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-audio.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-audio.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-layout-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-layout-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-layout.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-layout.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-paint-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-paint-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-paint.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-paint.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/script-tag.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/script-tag.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/script-tag.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/script-tag.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-classic.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-classic.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-classic.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-classic.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-import-data.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-import-data.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-import.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-import.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-import.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-import.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-module.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-module.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-module.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-module.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/w3c-import.log (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-classic.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-classic.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-classic.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-classic.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-import-data.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-import-data.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-import.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-import.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-import.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-import.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-module.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-module.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-module.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-module.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-animation-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-animation-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-animation.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-animation.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-audio-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-audio-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-audio.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-audio.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-layout-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-layout-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-layout.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-layout.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-paint-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-paint-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-paint.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-paint.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/script-tag.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/script-tag.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/script-tag.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/script-tag.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-classic.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-classic.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-classic.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-classic.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-import-data.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-import-data.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-import.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-import.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-import.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-import.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-module.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-module.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-module.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-module.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/w3c-import.log (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-classic.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-classic.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-classic.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-classic.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-import-data.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-import-data.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-import.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-import.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-import.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-import.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-module.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-module.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-module.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-module.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-animation-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-animation-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-animation.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-animation.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-audio-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-audio-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-audio.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-audio.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-layout-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-layout-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-layout.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-layout.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-paint-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-paint-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-paint.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-paint.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/script-tag.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/script-tag.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/script-tag.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/script-tag.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-classic.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-classic.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-classic.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-classic.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-import-data.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-import-data.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-import.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-import.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-import.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-import.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-module.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-module.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-module.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-module.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/w3c-import.log (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-classic.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-classic.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-classic.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-classic.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-import-data.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-import-data.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-import.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-import.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-import.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-import.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-module.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-module.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-module.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-module.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-animation-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-animation-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-animation.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-animation.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-audio-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-audio-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-audio.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-audio.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-layout-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-layout-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-layout.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-layout.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-paint-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-paint-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-paint.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-paint.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/script-tag.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/script-tag.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/script-tag.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/script-tag.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-classic.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-classic.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-classic.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-classic.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-import-data.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-import-data.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-import.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-import.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-import.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-import.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-module.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-module.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-module.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-module.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/w3c-import.log (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-classic.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-classic.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-classic.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-classic.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-import-data.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-import-data.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-import.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-import.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-import.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-import.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-module.http-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-module.http.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-module.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-module.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-animation-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-animation-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-animation.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-animation.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-audio-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-audio-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-audio.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-audio.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-layout-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-layout-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-layout.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-layout.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-paint-import-data.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-paint-import-data.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-paint.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-paint.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/generic/duplicate-directive.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/generic/filesystem-urls-match-filesystem.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/generic/generic-0_1-img-src.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/generic/generic-0_10.sub.html (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/generic/generic-0_8_1.sub.html (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/generic/generic-0_9.sub.html (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/generic/invalid-characters-in-policy-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/generic/invalid-characters-in-policy.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/generic/no-default-src.sub.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/generic/only-valid-whitespaces-are-allowed.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/generic/policy-inherited-correctly-by-plznavigate.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/generic/support/304-response.py (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/generic/test-case.sub.js (added)
-
imported/w3c/web-platform-tests/content-security-policy/generic/w3c-import.log (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/img-src/icon-allowed.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/img-src/icon-blocked.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/img-src/img-src-self-unique-origin.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/img-src/report-blocked-data-uri.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/blob-url-inherits-from-initiator.sub-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/blob-url-inherits-from-initiator.sub.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/document-write-iframe.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/history-iframe.sub-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/history-iframe.sub.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/history.sub-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/history.sub.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/iframe-all-local-schemes.sub-expected.txt (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/iframe-all-local-schemes.sub.html (modified) (5 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/inheritance-from-initiator.sub-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/inheritance-from-initiator.sub.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/javascript-url-open-in-main-window-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/javascript-url-open-in-main-window.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/javascript-url-srcdoc-cross-origin-iframe-inheritance-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/javascript-url-srcdoc-cross-origin-iframe-inheritance.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/location-reload-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/location-reload.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/sandboxed-blob-scheme.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/sandboxed-data-scheme.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/support/iframe-do.sub.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/support/javascript-url-srcdoc-cross-origin-iframe-inheritance-helper.sub.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/support/message-opener-and-navigate-back.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/support/message-top-and-navigate-back.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/support/navigate-parent-to-blob.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/support/navigate-self-to-blob.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/support/navigate-self-to-javascript.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/support/postmessage-opener.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/support/postmessage-top.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/support/w3c-import.log (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/unsandboxed-blob-scheme.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/unsandboxed-data-scheme.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/w3c-import.log (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/window-open-local-after-network-scheme.sub-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/inheritance/window-open-local-after-network-scheme.sub.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicated-inheritance-expected.txt (deleted)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicated-inheritance.html (deleted)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicated-script-expected.txt (deleted)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicated-script.html (deleted)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicatedworker-connect-src-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicatedworker-connect-src.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicatedworker-connect-src.html.sub.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicatedworker-report-only-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicatedworker-report-only.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicatedworker-report-only.html.sub.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicatedworker-script-src-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicatedworker-script-src.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicatedworker-script-src.html.sub.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/serviceworker-connect-src.https.sub-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/serviceworker-connect-src.https.sub.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/serviceworker-report-only.https.sub-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/serviceworker-report-only.https.sub.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/serviceworker-script-src.https.sub-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/serviceworker-script-src.https.sub.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/shared-inheritance.html (deleted)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/shared-script-expected.txt (deleted)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/shared-script.html (deleted)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/sharedworker-connect-src.sub-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/sharedworker-connect-src.sub.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/sharedworker-report-only.sub-expected.txt (moved) (moved from trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/shared-inheritance-expected.txt )
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/sharedworker-report-only.sub.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/sharedworker-script-src.sub-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/sharedworker-script-src.sub.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/support/connect-src-allow.sub.js (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/support/connect-src-self-report-only.sub.js (added)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/support/connect-src-self-report-only.sub.js.sub.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/support/connect-src-self.sub.js (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/support/script-src-allow.sub.js (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/support/script-src-self.sub.js (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/support/w3c-import.log (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/inside-worker/w3c-import.log (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/media-src/media-src-7_1_2.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/media-src/media-src-7_2_2.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/media-src/media-src-7_3.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/media-src/media-src-blocked.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/meta/meta-outside-head.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/navigate-to/anchor-navigation-always-allowed.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/navigate-to/parent-navigates-child-blocked.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/navigate-to/support/delayed_frame.py (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/navigate-to/support/form_action_navigation.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/navigate-to/support/form_action_navigation.sub.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/navigate-to/support/href_location_navigation.sub.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/navigate-to/support/link_click_navigation.sub.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/navigate-to/support/meta_refresh_navigation.sub.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/navigate-to/support/navigate_parent.sub.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/navigate-to/support/redirect_to_post_message_to_frame_owner.py (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/navigate-to/support/spv-test-iframe1.sub.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/navigation/javascript-url-navigation-inherits-csp-expected.txt (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/navigation/support/test_csp_self_window.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/navigation/support/test_csp_self_window.sub.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/navigation/to-javascript-url-frame-src.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/object-src/object-src-no-url-allowed.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/object-src/object-src-no-url-allowed.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/object-src/object-src-url-allowed.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/object-src/object-src-url-allowed.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/object-src/object-src-url-embed-allowed.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/object-src/object-src-url-embed-allowed.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/object-src/object-src-url-redirect-allowed.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/object-src/object-src-url-redirect-allowed.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugin-types-ignored-expected.txt (moved) (moved from trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-nourl-allowed-expected.txt )
-
imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugin-types-ignored.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugin-types-ignored.html.sub.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-empty.sub-expected.txt (deleted)
-
imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-empty.sub.html (deleted)
-
imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-mismatched-data-expected.txt (deleted)
-
imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-mismatched-data.html (deleted)
-
imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-mismatched-url-expected.txt (deleted)
-
imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-mismatched-url.html (deleted)
-
imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-notype-data-expected.txt (deleted)
-
imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-notype-data.html (deleted)
-
imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-notype-url-expected.txt (deleted)
-
imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-notype-url.html (deleted)
-
imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-nourl-allowed.html (deleted)
-
imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-nourl-allowed.html.sub.headers (deleted)
-
imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-nourl-blocked-expected.txt (deleted)
-
imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-nourl-blocked.html (deleted)
-
imported/w3c/web-platform-tests/content-security-policy/plugin-types/w3c-import.log (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-allowed.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-blocked-by-default-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-blocked-by-default.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-header-allowed.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-header-blocked-by-default-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-header-blocked-by-default.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-header-blocked-by-default.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-header-blocked.html (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-header-blocked.html.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/prefetch-src/w3c-import.log (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting-api/report-to-directive-allowed-in-meta.https.sub-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/reporting-api/report-to-directive-allowed-in-meta.https.sub.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/reporting-api/report-to-directive-allowed-in-meta.https.sub.html.sub.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-doesnt-send-reports-without-violation.https.sub.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-report-only-sends-reports-on-violation.https.sub.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-report-to-only-sends-reports-to-first-endpoint.https.sub.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-report-to-overrides-report-uri-1.https.sub.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-report-to-overrides-report-uri-2.https.sub.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-sends-reports-on-violation.https.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-sends-reports-on-violation.https.sub.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-works-on-frame-ancestors.https.sub-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-works-on-frame-ancestors.https.sub.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-works-on-frame-ancestors.https.sub.html.sub.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-works-on-frame-src.https.sub.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting-api/support (added)
-
imported/w3c/web-platform-tests/content-security-policy/reporting-api/support/non-embeddable-frame.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/reporting-api/support/non-embeddable-frame.html.sub.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/reporting-api/support/w3c-import.log (added)
-
imported/w3c/web-platform-tests/content-security-policy/reporting-api/w3c-import.log (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/multiple-report-policies.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/multiple-report-policies.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/post-redirect-stacktrace.https.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-and-enforce.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-and-enforce.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-blocked-data-uri.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-blocked-data-uri.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-blocked-uri-cross-origin.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-blocked-uri-cross-origin.sub.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-blocked-uri.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-blocked-uri.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-cross-origin-no-cookies.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-cross-origin-no-cookies.sub.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-frame-ancestors-with-x-frame-options.sub-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-frame-ancestors-with-x-frame-options.sub.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-frame-ancestors.sub-expected.txt (copied) (copied from trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-nourl-allowed-expected.txt )
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-frame-ancestors.sub.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-multiple-violations-01.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-multiple-violations-01.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-multiple-violations-02.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-multiple-violations-02.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-only-in-meta.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-only-unsafe-eval.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-only-unsafe-eval.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-original-url-on-mixed-content-frame.https.sub.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-original-url.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-original-url.sub.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-same-origin-with-cookies.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-same-origin-with-cookies.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-effective-directive.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-effective-directive.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-from-inline-javascript.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-from-inline-javascript.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-from-javascript.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-from-javascript.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-multiple-reversed.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-multiple-reversed.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-multiple.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-multiple.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-scheme-relative.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-scheme-relative.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/support/generate-csp-report.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/support/not-embeddable-frame.py (added)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/support/w3c-import.log (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/reporting/w3c-import.log (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/sandbox/meta-element.sub-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/sandbox/meta-element.sub.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/sandbox/service-worker-sandbox.https-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/sandbox/service-worker-sandbox.https.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/sandbox/shared-worker-sandbox-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/sandbox/shared-worker-sandbox.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/sandbox/support/empty.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/sandbox/support/post-origin-on-load-worker.js (added)
-
imported/w3c/web-platform-tests/content-security-policy/sandbox/support/sandboxed-service-worker.js (added)
-
imported/w3c/web-platform-tests/content-security-policy/sandbox/support/sandboxed-service-worker.js.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/sandbox/support/sandboxed-shared-worker.js (added)
-
imported/w3c/web-platform-tests/content-security-policy/sandbox/support/sandboxed-shared-worker.js.headers (added)
-
imported/w3c/web-platform-tests/content-security-policy/sandbox/support/w3c-import.log (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/sandbox/w3c-import.log (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/10_1_support_2.js (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/eval-allowed-in-report-only-mode-and-sends-report-expected.txt (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/eval-allowed-in-report-only-mode-and-sends-report.html (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/eval-allowed-in-report-only-mode-and-sends-report.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/injected-inline-script-blocked.sub-expected.txt (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/injected-inline-script-blocked.sub.html (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/javascript-window-open-blocked.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-1_10.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-1_4.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-1_4_1.html (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-1_4_2.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_double_policy_honor_source_expressions.sub-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_double_policy_honor_source_expressions.sub.html (moved) (moved from trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_double_policy_honor_source_expressions.html )
-
imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_double_policy_honor_source_expressions.sub.html.headers (moved) (moved from trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_double_policy_honor_source_expressions.html.headers )
-
imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_eval.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_hashes.html (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_hashes.html.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/scripthash-allowed.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/scripthash-basic-blocked.sub.html (modified) (3 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/scripthash-case-insensitive.sub-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/scripthash-case-insensitive.sub.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/scripthash-default-src.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/scripthash-ignore-unsafeinline.sub.html (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/scriptnonce-allowed.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/scriptnonce-and-scripthash.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/scriptnonce-ignore-unsafeinline.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/scriptnonce-redirect.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/support/w3c-import.log (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/support/worker-importscripts.js (deleted)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/support/worker-set-timeout.js (deleted)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/support/worker-with-script-src-none-importscripts.js (added)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/support/worker-with-script-src-none-importscripts.js.sub.headers (moved) (moved from trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/support/worker-importscripts.js.sub.headers )
-
imported/w3c/web-platform-tests/content-security-policy/script-src/support/worker-with-script-src-none-set-timeout.js (added)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/support/worker-with-script-src-none-set-timeout.js.sub.headers (moved) (moved from trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/support/worker-set-timeout.js.sub.headers )
-
imported/w3c/web-platform-tests/content-security-policy/script-src/w3c-import.log (modified) (3 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/worker-data-set-timeout.sub-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/worker-data-set-timeout.sub.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/worker-eval-blocked.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/worker-importscripts-blocked.sub-expected.txt (deleted)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/worker-importscripts-blocked.sub.html (deleted)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/worker-importscripts.sub-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/worker-importscripts.sub.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/worker-set-timeout-blocked.sub-expected.txt (deleted)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/worker-set-timeout-blocked.sub.html (deleted)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/worker-set-timeout.sub-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/script-src/worker-set-timeout.sub.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/img-src-redirect.sub-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/img-src-redirect.sub.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/inside-service-worker.https.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/script-sample-no-opt-in.html (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/script-sample.html (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/securitypolicyviolation-block-cross-origin-image-from-script.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/securitypolicyviolation-block-cross-origin-image.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/securitypolicyviolation-block-image-from-script.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/securitypolicyviolation-block-image.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/source-file-blob-scheme-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/source-file-blob-scheme.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/source-file-data-scheme-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/source-file-data-scheme.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/style-sample-no-opt-in.html (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/style-sample.html (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/w3c-import.log (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/spec.src.json (added)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/injected-inline-style-allowed.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/inline-style-allowed-while-cloning-objects.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/inline-style-allowed.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/style-allowed.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/style-blocked.sub-expected.txt (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/style-blocked.sub.html (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-hash-allowed.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-hash-blocked.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-hash-case-insensitive-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-hash-case-insensitive.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-hash-default-src-allowed.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-imported-style-allowed.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-imported-style-blocked.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-injected-inline-style-allowed.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-injected-inline-style-blocked.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-injected-stylesheet-allowed.sub-expected.txt (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-injected-stylesheet-allowed.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-injected-stylesheet-blocked.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-inline-style-allowed.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-inline-style-attribute-allowed.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-inline-style-attribute-blocked.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-inline-style-blocked.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-inline-style-nonce-allowed.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-inline-style-nonce-blocked-error-event.html (modified) (3 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-inline-style-nonce-blocked.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-multiple-policies-multiple-hashing-algorithms.html.sub.headers (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-none-blocked.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-star-allowed.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-stylesheet-nonce-allowed.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-stylesheet-nonce-blocked.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/stylehash-allowed.sub.html (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/stylehash-basic-blocked.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/style-src/w3c-import.log (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/support/alertAssert.sub.js (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/support/checkReport.sub.js (modified) (3 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/support/echo-policy.py (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/support/logTest.sub.js (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/support/prefetch-helper.js (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/support/resource.py (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/support/testharness-helper.js (modified) (3 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/support/w3c-import.log (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/eval-blocked-in-about-blank-iframe.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/eval-in-iframe-expected.txt (added)
-
imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/eval-in-iframe.html (added)
-
imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/eval-scripts-setInterval-allowed.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/eval-scripts-setInterval-blocked.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/eval-scripts-setTimeout-allowed.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/eval-scripts-setTimeout-blocked.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/function-constructor-blocked.sub.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/support (added)
-
imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/support/echo-eval-with-policy.py (added)
-
imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/support/w3c-import.log (added)
-
imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/w3c-import.log (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/unsafe-hashes/javascript_src_allowed-href_blank.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/unsafe-hashes/javascript_src_allowed-window_location.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/unsafe-hashes/javascript_src_denied_missing_unsafe_hashes-window_location.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/unsafe-hashes/javascript_src_denied_wrong_hash-window_location.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/unsafe-hashes/script_event_handlers_allowed.html (modified) (1 diff)
-
imported/w3c/web-platform-tests/content-security-policy/unsafe-hashes/support/child_window_location_navigate.sub.html (modified) (2 diffs)
-
imported/w3c/web-platform-tests/content-security-policy/w3c-import.log (modified) (1 diff)
-
imported/w3c/web-platform-tests/reporting (added)
-
imported/w3c/web-platform-tests/reporting/META.yml (added)
-
imported/w3c/web-platform-tests/reporting/bufferSize-expected.txt (added)
-
imported/w3c/web-platform-tests/reporting/bufferSize.html (added)
-
imported/w3c/web-platform-tests/reporting/disconnect-expected.txt (added)
-
imported/w3c/web-platform-tests/reporting/disconnect.html (added)
-
imported/w3c/web-platform-tests/reporting/generateTestReport-expected.txt (added)
-
imported/w3c/web-platform-tests/reporting/generateTestReport.html (added)
-
imported/w3c/web-platform-tests/reporting/idlharness.any-expected.txt (added)
-
imported/w3c/web-platform-tests/reporting/idlharness.any.html (added)
-
imported/w3c/web-platform-tests/reporting/idlharness.any.js (added)
-
imported/w3c/web-platform-tests/reporting/idlharness.any.worker-expected.txt (added)
-
imported/w3c/web-platform-tests/reporting/idlharness.any.worker.html (added)
-
imported/w3c/web-platform-tests/reporting/nestedReport-expected.txt (added)
-
imported/w3c/web-platform-tests/reporting/nestedReport.html (added)
-
imported/w3c/web-platform-tests/reporting/order-expected.txt (added)
-
imported/w3c/web-platform-tests/reporting/order.html (added)
-
imported/w3c/web-platform-tests/reporting/path-absolute-endpoint.https.sub-expected.txt (added)
-
imported/w3c/web-platform-tests/reporting/path-absolute-endpoint.https.sub.html (added)
-
imported/w3c/web-platform-tests/reporting/path-absolute-endpoint.https.sub.html.sub.headers (added)
-
imported/w3c/web-platform-tests/reporting/resources (added)
-
imported/w3c/web-platform-tests/reporting/resources/README.md (added)
-
imported/w3c/web-platform-tests/reporting/resources/fail.png (added)
-
imported/w3c/web-platform-tests/reporting/resources/report-helper.js (added)
-
imported/w3c/web-platform-tests/reporting/resources/report.py (moved) (moved from trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/support/report.py )
-
imported/w3c/web-platform-tests/reporting/resources/w3c-import.log (added)
-
imported/w3c/web-platform-tests/reporting/w3c-import.log (added)
-
platform/mac-wk1/TestExpectations (modified) (1 diff)
-
platform/mac-wk1/imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-same-none-block-expected.txt (modified) (1 diff)
-
platform/mac-wk1/imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-same-self-block-expected.txt (modified) (1 diff)
-
platform/mac-wk1/imported/w3c/web-platform-tests/content-security-policy/inside-worker (added)
-
platform/mac-wk1/imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicatedworker-report-only-expected.txt (added)
-
tests-options.json (modified) (1 diff)
Legend:
- Unmodified
- Added
- Removed
-
trunk/LayoutTests/ChangeLog
r279831 r279838 1 2021-07-12 Chris Dumez <cdumez@apple.com> 2 3 Resync content-security-policy web-platform-tests from upstream 4 https://bugs.webkit.org/show_bug.cgi?id=227651 5 6 Reviewed by Sam Weinig. 7 8 * TestExpectations: 9 * tests-options.json: 10 1 11 2021-07-12 Eric Hutchison <ehutchison@apple.com> 2 12 -
trunk/LayoutTests/TestExpectations
r279819 r279838 412 412 imported/w3c/web-platform-tests/html/webappapis/timers/negative-settimeout.any.worker.html [ DumpJSConsoleLogInStdErr ] 413 413 imported/w3c/web-platform-tests/html/webappapis/user-prompts/print-during-beforeunload.html [ DumpJSConsoleLogInStdErr ] 414 imported/w3c/web-platform-tests/reporting/disconnect.html [ DumpJSConsoleLogInStdErr ] 414 415 imported/w3c/web-platform-tests/streams/readable-streams/patched-global.any.html [ DumpJSConsoleLogInStdErr ] 415 416 imported/w3c/web-platform-tests/streams/transform-streams/terminate.any.html [ DumpJSConsoleLogInStdErr ] … … 440 441 imported/w3c/web-platform-tests/clipboard-apis/feature-policy/clipboard-read/clipboard-read-enabled-by-feature-policy.tentative.https.sub.html [ Skip ] 441 442 imported/w3c/web-platform-tests/clipboard-apis/feature-policy/clipboard-read/clipboard-read-enabled-on-self-origin-by-feature-policy.tentative.https.sub.html [ Skip ] 443 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-import.http.html [ Skip ] 444 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-import.https.html [ Skip ] 445 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-import-data.http.html [ Skip ] 446 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-import-data.https.html [ Skip ] 447 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-import.http.html [ Skip ] 448 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-import.https.html [ Skip ] 449 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-import-data.http.html [ Skip ] 450 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-import-data.https.html [ Skip ] 451 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-import.http.html [ Skip ] 452 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-import.https.html [ Skip ] 453 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-import-data.http.html [ Skip ] 454 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-import-data.https.html [ Skip ] 455 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-import.http.html [ Skip ] 456 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-import.https.html [ Skip ] 457 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-import-data.http.html [ Skip ] 458 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-import-data.https.html [ Skip ] 459 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-import.http.html [ Skip ] 460 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-import.https.html [ Skip ] 461 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-import-data.http.html [ Skip ] 462 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-import-data.https.html [ Skip ] 463 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-import.http.html [ Skip ] 464 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-import.https.html [ Skip ] 465 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-import-data.http.html [ Skip ] 466 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-import-data.https.html [ Skip ] 467 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-import.http.html [ Skip ] 468 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-import.https.html [ Skip ] 469 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-import-data.http.html [ Skip ] 470 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-import-data.https.html [ Skip ] 471 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-import.http.html [ Skip ] 472 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-import.https.html [ Skip ] 473 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-import-data.http.html [ Skip ] 474 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-import-data.https.html [ Skip ] 475 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-import.http.html [ Skip ] 476 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-import.https.html [ Skip ] 477 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-import-data.http.html [ Skip ] 478 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-import-data.https.html [ Skip ] 479 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-import.http.html [ Skip ] 480 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-import.https.html [ Skip ] 481 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-import-data.http.html [ Skip ] 482 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-import-data.https.html [ Skip ] 483 imported/w3c/web-platform-tests/content-security-policy/inheritance/history-iframe.sub.html [ Skip ] 484 imported/w3c/web-platform-tests/content-security-policy/inheritance/javascript-url-open-in-main-window.html [ Skip ] 485 imported/w3c/web-platform-tests/content-security-policy/inheritance/javascript-url-srcdoc-cross-origin-iframe-inheritance.html [ Skip ] 486 imported/w3c/web-platform-tests/content-security-policy/inheritance/location-reload.html [ Skip ] 487 imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicatedworker-connect-src.html [ Skip ] 488 imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicatedworker-script-src.html [ Skip ] 489 imported/w3c/web-platform-tests/content-security-policy/inside-worker/serviceworker-connect-src.https.sub.html [ Skip ] 490 imported/w3c/web-platform-tests/content-security-policy/inside-worker/serviceworker-script-src.https.sub.html [ Skip ] 491 imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-blocked-by-default.html [ Skip ] 492 imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-header-blocked-by-default.html [ Skip ] 493 imported/w3c/web-platform-tests/content-security-policy/reporting-api/report-to-directive-allowed-in-meta.https.sub.html [ Skip ] 494 imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_double_policy_honor_source_expressions.sub.html [ Skip ] 495 imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/img-src-redirect.sub.html [ Skip ] 496 imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/source-file-blob-scheme.html [ Skip ] 497 imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/source-file-data-scheme.html [ Skip ] 442 498 imported/w3c/web-platform-tests/cookies/domain/domain-attribute-host-with-and-without-leading-period.sub.https.html [ Skip ] 443 499 imported/w3c/web-platform-tests/cookies/domain/domain-attribute-host-with-leading-period.sub.https.html [ Skip ] … … 547 603 imported/w3c/web-platform-tests/html/semantics/interactive-elements/the-summary-element/anchor-with-inline-element.html [ Skip ] 548 604 imported/w3c/web-platform-tests/html/semantics/scripting-1/the-script-element/json-module/parse-error.tentative.html [ Skip ] 605 imported/w3c/web-platform-tests/reporting/path-absolute-endpoint.https.sub.html [ Skip ] 549 606 imported/w3c/web-platform-tests/workers/interfaces/WorkerGlobalScope/onerror/message-module-Error.html [ Skip ] 550 607 [ Debug ] imported/w3c/web-platform-tests/css/css-backgrounds/background-size/background-size-near-zero-svg.html [ Skip ] … … 665 722 # Newly imported WPT tests that are flaky. 666 723 webkit.org/b/227649 imported/w3c/web-platform-tests/beacon/beacon-basic.https.window.html [ Failure Pass ] 724 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-audio.https.html [ Failure Pass ] 725 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/script-tag.http.html [ Failure Pass ] 726 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/script-tag.https.html [ Failure Pass ] 727 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-audio.https.html [ Failure Pass ] 728 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/script-tag.http.html [ Failure Pass ] 729 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/script-tag.https.html [ Failure Pass ] 730 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-audio-import-data.https.html [ Failure Pass ] 731 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-audio.https.html [ Failure Pass ] 732 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/script-tag.http.html [ Failure Pass ] 733 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/script-tag.https.html [ Failure Pass ] 734 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-audio-import-data.https.html [ Failure Pass ] 735 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-audio.https.html [ Failure Pass ] 736 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/script-tag.http.html [ Failure Pass ] 737 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/script-tag.https.html [ Failure Pass ] 738 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-audio-import-data.https.html [ Failure Pass ] 739 imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-audio.https.html [ Failure Pass ] 740 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-audio.https.html [ Failure Pass ] 741 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/script-tag.http.html [ Failure Pass ] 742 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/script-tag.https.html [ Failure Pass ] 743 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-audio.https.html [ Failure Pass ] 744 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/script-tag.http.html [ Failure Pass ] 745 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/script-tag.https.html [ Failure Pass ] 746 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-audio-import-data.https.html [ Failure Pass ] 747 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-audio.https.html [ Failure Pass ] 748 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/script-tag.http.html [ Failure Pass ] 749 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/script-tag.https.html [ Failure Pass ] 750 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-audio-import-data.https.html [ Failure Pass ] 751 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-audio.https.html [ Failure Pass ] 752 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/script-tag.http.html [ Failure Pass ] 753 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/script-tag.https.html [ Failure Pass ] 754 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-audio-import-data.https.html [ Failure Pass ] 755 imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-audio.https.html [ Failure Pass ] 667 756 imported/w3c/web-platform-tests/cookies/name/name.html [ Failure Pass ] 668 757 imported/w3c/web-platform-tests/cookies/prefix/__secure.header.https.html [ Failure Pass ] … … 705 794 imported/w3c/web-platform-tests/html/semantics/embedded-content/the-iframe-element/cross-origin-to-whom-part-2.window.html [ Failure Pass ] 706 795 imported/w3c/web-platform-tests/html/semantics/forms/form-submission-0/multipart-formdata.window.html [ Failure Pass ] 796 imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-works-on-frame-ancestors.https.sub.html [ Failure Pass ] 707 797 imported/w3c/web-platform-tests/user-timing/clearMarks.html [ Failure Pass ] 708 798 imported/w3c/web-platform-tests/user-timing/mark.html [ Failure Pass ] … … 841 931 imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-header-allowed.html [ Skip ] 842 932 imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-header-blocked.html [ Skip ] 843 imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicated-inheritance.html [ Skip ]844 imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicated-script.html [ Skip ]845 933 imported/w3c/web-platform-tests/content-security-policy/style-src/stylenonce-allowed.sub.html [ Skip ] 846 934 imported/w3c/web-platform-tests/content-security-policy/style-src/stylehash-basic-blocked.sub.html [ Skip ] … … 849 937 imported/w3c/web-platform-tests/content-security-policy/style-src/stylenonce-blocked.sub.html [ Skip ] 850 938 imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-inline-style-nonce-blocked-error-event.html [ Skip ] 851 imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-mismatched-url.html [ Skip ]852 imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-mismatched-data.html [ Skip ]853 imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-notype-data.html [ Skip ]854 imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-nourl-blocked.html [ Skip ]855 imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-notype-url.html [ Skip ]856 imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-empty.sub.html [ Skip ]857 939 imported/w3c/web-platform-tests/content-security-policy/child-src/child-src-cross-origin-load.sub.html [ Skip ] 858 940 imported/w3c/web-platform-tests/content-security-policy/inheritance/document-write-iframe.html [ Skip ] -
trunk/LayoutTests/imported/w3c/ChangeLog
r279819 r279838 1 2021-07-12 Chris Dumez <cdumez@apple.com> 2 3 Resync content-security-policy web-platform-tests from upstream 4 https://bugs.webkit.org/show_bug.cgi?id=227651 5 6 Reviewed by Sam Weinig. 7 8 Resync content-security-policy web-platform-tests from upstream 2c19d6ee62676ac90146. 9 10 * resources/import-expectations.json: 11 * resources/resource-files.json: 12 * web-platform-tests/content-security-policy/*: Updated. 13 * web-platform-tests/reporting/*: Imported. 14 1 15 2021-07-12 Rob Buis <rbuis@igalia.com> 2 16 -
trunk/LayoutTests/imported/w3c/resources/import-expectations.json
r279769 r279838 379 379 "web-platform-tests/referrer-policy": "import", 380 380 "web-platform-tests/remote-playback": "import", 381 "web-platform-tests/reporting": "import", 381 382 "web-platform-tests/requestidlecallback": "import", 382 383 "web-platform-tests/resize-observer": "import", -
trunk/LayoutTests/imported/w3c/resources/resource-files.json
r279819 r279838 99 99 "web-platform-tests/compat/webkit-box-fixed-position-child.html", 100 100 "web-platform-tests/content-security-policy/README.html", 101 "web-platform-tests/content-security-policy/embedded-enforcement/support/embed-img-and-message-top.html", 101 102 "web-platform-tests/content-security-policy/embedded-enforcement/support/executor.html", 102 103 "web-platform-tests/content-security-policy/form-action/support/post-message-to-opener.sub.html", … … 112 113 "web-platform-tests/content-security-policy/generic/support/sandboxed-eval.sub.html", 113 114 "web-platform-tests/content-security-policy/inheritance/support/empty.html", 115 "web-platform-tests/content-security-policy/inheritance/support/iframe-do.sub.html", 116 "web-platform-tests/content-security-policy/inheritance/support/javascript-url-srcdoc-cross-origin-iframe-inheritance-helper.sub.html", 117 "web-platform-tests/content-security-policy/inheritance/support/message-opener-and-navigate-back.html", 118 "web-platform-tests/content-security-policy/inheritance/support/message-top-and-navigate-back.html", 119 "web-platform-tests/content-security-policy/inheritance/support/navigate-parent-to-blob.html", 114 120 "web-platform-tests/content-security-policy/inheritance/support/navigate-self-to-blob.html", 121 "web-platform-tests/content-security-policy/inheritance/support/navigate-self-to-javascript.html", 122 "web-platform-tests/content-security-policy/inheritance/support/postmessage-opener.html", 123 "web-platform-tests/content-security-policy/inheritance/support/postmessage-top.html", 115 124 "web-platform-tests/content-security-policy/inheritance/support/srcdoc-child-frame.html", 116 125 "web-platform-tests/content-security-policy/navigate-to/support/post_message_to_frame_owner.html", … … 119 128 "web-platform-tests/content-security-policy/navigate-to/support/spv-test-iframe3.sub.html", 120 129 "web-platform-tests/content-security-policy/navigation/support/frame-with-csp.sub.html", 130 "web-platform-tests/content-security-policy/reporting-api/support/non-embeddable-frame.html", 121 131 "web-platform-tests/content-security-policy/reporting/support/generate-csp-report.html", 132 "web-platform-tests/content-security-policy/sandbox/support/empty.html", 122 133 "web-platform-tests/content-security-policy/sandbox/support/sandboxed-data-iframe.sub.html", 123 134 "web-platform-tests/content-security-policy/sandbox/support/sandboxed-eval.sub.html", -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/README.html
r254133 r279838 72 72 Pragma: no-cache 73 73 Set-Cookie: <span class=highlight2>script-src-1_1</span>={{$id:uuid()}}; Path=<span class=highlight2>/content-security-policy/script-src/</span> 74 Content-Security-Policy: <span class=highlight1>script-src 'self'</span>; report-uri <span class=highlight2> ..</span>/support/report.py?op=put&reportID;={{$id}}74 Content-Security-Policy: <span class=highlight1>script-src 'self'</span>; report-uri <span class=highlight2></span>/reporting/resources/report.py?op=put&reportID;={{$id}} 75 75 </code></pre> 76 76 <p>This sets some headers to prevent caching (just so we are more likely to see our latest changes if we're actively developing this test) sets a cookie (more on that later) and sets the relevant <span class=code>Content-Security-Policy</span> header for our test case.</p> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/base-uri/report-uri-does-not-respect-base-uri.sub.html.sub.headers
r246330 r279838 3 3 Pragma: no-cache 4 4 Set-Cookie: report-uri-does-not-respect-base-uri={{$id:uuid()}}; Path=/content-security-policy/base-uri 5 Content-Security-Policy: script-src 'self' 'unsafe-inline'; img-src 'none'; report-uri ../support/report.py?op=put&reportID={{$id}}5 Content-Security-Policy: script-src 'self' 'unsafe-inline'; img-src 'none'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/blob/blob-urls-match-blob.sub.html
r246330 r279838 4 4 <head> 5 5 <!-- Programmatically converted from a WebKit Reftest, please forgive resulting idiosyncracies.--> 6 <meta http-equiv="Content-Security-Policy" content="script-src 'self' 'unsafe-inline' blob:; connect-src 'self';"> 6 <meta http-equiv="Content-Security-Policy" content="script-src 'self' 'unsafe-inline' blob:; connect-src 'self';"> 7 7 <title>blob-urls-match-blob</title> 8 8 <script src="/resources/testharness.js"></script> … … 20 20 log("FAIL"); 21 21 }); 22 22 23 23 function pass() { 24 24 log("PASS (1/1)"); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/blob/self-doesnt-match-blob.sub.html
r246330 r279838 21 21 log("violated-directive=" + e.violatedDirective); 22 22 }); 23 23 24 24 try { 25 25 var blob = new Blob([ -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/blob/star-doesnt-match-blob.sub.html
r246330 r279838 21 21 log("violated-directive=" + e.violatedDirective); 22 22 }); 23 23 24 24 try { 25 25 var blob = new Blob([ -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/child-src/child-src-about-blank-allowed-by-default.sub.html
r246330 r279838 16 16 window.addEventListener("securitypolicyviolation", t.unreached_func("Should not have fired any events")); 17 17 </script> 18 18 19 19 <iframe src="about:blank"></iframe> 20 20 <object type="text/html" data="about:blank"></object> 21 21 22 22 <div id="log"></div> 23 23 24 24 <script> 25 25 t.done(); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/child-src/child-src-about-blank-allowed-by-scheme.sub.html
r246330 r279838 14 14 window.addEventListener("securitypolicyviolation", t.unreached_func("Should not have fired any events")); 15 15 </script> 16 16 17 17 <iframe src="about:blank"></iframe> 18 18 <div id="log"></div> 19 19 20 20 <script> 21 21 t.done(); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/child-src/child-src-allowed.sub.html
r246330 r279838 12 12 alert_assert(event.data); 13 13 }, false); 14 14 15 15 window.addEventListener("securitypolicyviolation", function(e) { 16 16 alert_assert("Fail"); … … 28 28 for (var i = 0; i < expected_alerts.length; i++) { 29 29 if (expected_alerts[i] == msg) { 30 assert_ true(expected_alerts[i] ==msg);30 assert_equals(expected_alerts[i], msg); 31 31 expected_alerts.splice(i, 1); 32 32 if (expected_alerts.length == 0) { -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/child-src/child-src-blocked.sub.html
r246330 r279838 13 13 alert_assert(event.data); 14 14 }, false); 15 15 16 16 window.addEventListener("securitypolicyviolation", function(e) { 17 17 log("violated-directive=" + e.violatedDirective); … … 26 26 for (var i = 0; i < expected_alerts.length; i++) { 27 27 if (expected_alerts[i] == msg) { 28 assert_ true(expected_alerts[i] ==msg);28 assert_equals(expected_alerts[i], msg); 29 29 expected_alerts.splice(i, 1); 30 30 if (expected_alerts.length == 0) { -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/child-src/child-src-conflicting-frame-src.sub.html
r246330 r279838 24 24 for (var i = 0; i < expected_alerts.length; i++) { 25 25 if (expected_alerts[i] == msg) { 26 assert_ true(expected_alerts[i] ==msg);26 assert_equals(expected_alerts[i], msg); 27 27 expected_alerts.splice(i, 1); 28 28 if (expected_alerts.length == 0) { -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/child-src/child-src-cross-origin-load.sub.html
r246330 r279838 29 29 for (var i = 0; i < expected_alerts.length; i++) { 30 30 if (expected_alerts[i] == msg) { 31 assert_ true(expected_alerts[i] ==msg);31 assert_equals(expected_alerts[i], msg); 32 32 expected_alerts.splice(i, 1); 33 33 if (expected_alerts.length == 0) { -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/child-src/child-src-redirect-blocked.sub.html
r246330 r279838 26 26 for (var i = 0; i < expected_alerts.length; i++) { 27 27 if (expected_alerts[i] == msg) { 28 assert_ true(expected_alerts[i] ==msg);28 assert_equals(expected_alerts[i], msg); 29 29 expected_alerts.splice(i, 1); 30 30 if (expected_alerts.length == 0) { -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/connect-src/shared-worker-connect-src-allowed.sub.html
r246330 r279838 17 17 log("violated-directive=" + e.violatedDirective); 18 18 }); 19 19 20 20 if(typeof SharedWorker != 'function') { 21 21 t_log.set_status(t_alert.NOTRUN, "No SharedWorker, cannot run test."); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/connect-src/shared-worker-connect-src-blocked.sub.html
r246330 r279838 9 9 <script src="/resources/testharnessreport.js"></script> 10 10 <script src='../support/logTest.sub.js?logs=["xhr blocked","TEST COMPLETE"]'></script> 11 <script src='../support/alertAssert.sub.js?alerts=[]'></script> 11 <script src='../support/alertAssert.sub.js?alerts=[]'></script> 12 12 </head> 13 13 … … 23 23 log("Fail"); 24 24 }); 25 25 26 26 if(typeof SharedWorker != 'function') { 27 27 t_log.set_status(t_log.NOTRUN, "No SharedWorker, cannot run test."); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/connect-src/worker-connect-src-allowed.sub.html
r246330 r279838 18 18 log('Fail'); 19 19 }); 20 20 21 21 try { 22 22 var worker = new Worker('/content-security-policy/connect-src/support/worker-make-xhr.sub.js'); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/connect-src/worker-connect-src-blocked.sub.html
r246330 r279838 22 22 log('Fail'); 23 23 }); 24 24 25 25 try { 26 26 var worker = new Worker('/content-security-policy/connect-src/support/worker-make-xhr-blocked.sub.js'); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/connect-src/worker-from-guid.sub.html
r246330 r279838 40 40 " xhr.open(" + 41 41 " 'GET'," + 42 " 'http:///content-security-policy/support/fail.asis'," + 42 " 'http:///content-security-policy/support/fail.asis'," + 43 43 " true" + 44 44 " );" + -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/allow_csp_from-header.html
r263605 r279838 10 10 <script> 11 11 var tests = [ 12 { "name": "Same origin iframes are always allowed.", 12 { "name": "Same origin iframes are always allowed.", 13 13 "origin": Host.SAME_ORIGIN, 14 "csp": "style-src 'unsafe-inline'; script-src 'unsafe-inline'", 14 "csp": "style-src 'unsafe-inline'; script-src 'unsafe-inline'", 15 15 "allow_csp_from": "¢¥§", 16 16 "expected": IframeLoad.EXPECT_LOAD, 17 17 "blockedURI": null}, 18 { "name": "Same origin iframes are allowed even if the Allow-CSP-From is empty.", 18 { "name": "Same origin iframes are allowed even if the Allow-CSP-From is empty.", 19 19 "origin": Host.SAME_ORIGIN, 20 "csp": "style-src 'unsafe-inline'; script-src 'unsafe-inline'", 20 "csp": "style-src 'unsafe-inline'; script-src 'unsafe-inline'", 21 21 "allow_csp_from": "", 22 22 "expected": IframeLoad.EXPECT_LOAD, 23 23 "blockedURI": null}, 24 { "name": "Same origin iframes are allowed even if the Allow-CSP-From is not present.", 24 { "name": "Same origin iframes are allowed even if the Allow-CSP-From is not present.", 25 25 "origin": Host.SAME_ORIGIN, 26 "csp": "style-src 'unsafe-inline'; script-src 'unsafe-inline'", 26 "csp": "style-src 'unsafe-inline'; script-src 'unsafe-inline'", 27 27 "allow_csp_from": null, 28 28 "expected": IframeLoad.EXPECT_LOAD, 29 29 "blockedURI": null}, 30 { "name": "Same origin iframes are allowed even if Allow-CSP-From does not match origin.", 30 { "name": "Same origin iframes are allowed even if Allow-CSP-From does not match origin.", 31 31 "origin": Host.SAME_ORIGIN, 32 "csp": "style-src 'unsafe-inline'; script-src 'unsafe-inline'", 32 "csp": "style-src 'unsafe-inline'; script-src 'unsafe-inline'", 33 33 "allow_csp_from": "http://example.com:888", 34 34 "expected": IframeLoad.EXPECT_LOAD, 35 35 "blockedURI": null}, 36 { "name": "Cross origin iframe with an empty Allow-CSP-From header gets blocked.", 36 { "name": "Cross origin iframe with an empty Allow-CSP-From header gets blocked.", 37 37 "origin": Host.CROSS_ORIGIN, 38 "csp": "script-src 'unsafe-inline'", 38 "csp": "script-src 'unsafe-inline'", 39 39 "allow_csp_from": "", 40 40 "expected": IframeLoad.EXPECT_BLOCK, 41 41 "blockedURI": null}, 42 { "name": "Cross origin iframe without Allow-CSP-From header gets blocked.", 42 { "name": "Cross origin iframe without Allow-CSP-From header gets blocked.", 43 43 "origin": Host.CROSS_ORIGIN, 44 "csp": "script-src 'unsafe-inline'", 44 "csp": "script-src 'unsafe-inline'", 45 45 "allow_csp_from": null, 46 46 "expected": IframeLoad.EXPECT_BLOCK, … … 48 48 { "name": "Cross origin iframe with correct Allow-CSP-From header is allowed.", 49 49 "origin": Host.CROSS_ORIGIN, 50 "csp": "style-src 'unsafe-inline'; script-src 'unsafe-inline'", 50 "csp": "style-src 'unsafe-inline'; script-src 'unsafe-inline'", 51 51 "allow_csp_from": getOrigin(), 52 52 "expected": IframeLoad.EXPECT_LOAD, 53 53 "blockedURI": null}, 54 { "name": "Iframe with improper Allow-CSP-From header gets blocked.", 54 { "name": "Iframe with improper Allow-CSP-From header gets blocked.", 55 55 "origin": Host.CROSS_ORIGIN, 56 "csp": "script-src 'unsafe-inline'", 56 "csp": "script-src 'unsafe-inline'", 57 57 "allow_csp_from": "* ¢¥§", 58 58 "expected": IframeLoad.EXPECT_BLOCK, … … 60 60 { "name": "Allow-CSP-From header with a star value allows cross origin frame.", 61 61 "origin": Host.CROSS_ORIGIN, 62 "csp": "script-src 'unsafe-inline'", 62 "csp": "script-src 'unsafe-inline'", 63 63 "allow_csp_from": "*", 64 64 "expected": IframeLoad.EXPECT_LOAD, 65 65 "blockedURI": null}, 66 { "name": "Star Allow-CSP-From header enforces EmbeddingCSP.", 66 { "name": "Star Allow-CSP-From header enforces EmbeddingCSP.", 67 67 "origin": Host.CROSS_ORIGIN, 68 "csp": "script-src 'nonce-123'", 68 "csp": "script-src 'nonce-123'", 69 69 "allow_csp_from": "*", 70 70 "expected": IframeLoad.EXPECT_LOAD, 71 71 "blockedURI": "inline"}, 72 { "name": "Allow-CSP-From header enforces EmbeddingCSP.", 72 { "name": "Allow-CSP-From header enforces EmbeddingCSP.", 73 73 "origin": Host.CROSS_ORIGIN, 74 "csp": "style-src 'none'; script-src 'nonce-123'", 74 "csp": "style-src 'none'; script-src 'nonce-123'", 75 75 "allow_csp_from": getOrigin(), 76 76 "expected": IframeLoad.EXPECT_LOAD, 77 77 "blockedURI": "inline"}, 78 { "name": "'self' in blanket enforced EmbeddingCSP matches the target response origin.", 79 "origin": Host.CROSS_ORIGIN, 80 "csp": "img-src 'self'", 81 "allow_csp_from": "*", 82 "expected": IframeLoad.EXPECT_LOAD, 83 "blockedURI": null}, 78 84 ]; 79 85 -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/required-csp-header-cascade.html
r246330 r279838 35 35 "expected1": null, 36 36 "expected2": "script-src 'unsafe-inline'; style-src 'self';"}, 37 { "name": "Test invalid policy on first iframe (bad directive )",38 "csp1": "default-src http://example.com; i nvalid-policy-name http://example.com",37 { "name": "Test invalid policy on first iframe (bad directive name)", 38 "csp1": "default-src http://example.com; i//nvalid-policy-name http://example.com", 39 39 "csp2": "script-src 'unsafe-inline'; style-src 'self';", 40 40 "expected1": null, … … 45 45 "expected1": null, 46 46 "expected2": "script-src 'unsafe-inline'; style-src 'self';"}, 47 { "name": "Test invalid policy on second iframe (bad directive )",47 { "name": "Test invalid policy on second iframe (bad directive name)", 48 48 "csp1": "script-src 'unsafe-inline'; style-src 'self';", 49 "csp2": "default-src http://example.com; i nvalid-policy-name http://example.com",49 "csp2": "default-src http://example.com; i//nvalid-policy-name http://example.com", 50 50 "expected1": "script-src 'unsafe-inline'; style-src 'self';", 51 51 "expected2": "script-src 'unsafe-inline'; style-src 'self';"}, -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/required_csp-header-crlf.html
r246330 r279838 2 2 <html> 3 3 <head> 4 <title>Embedded Enforcement: Sec-Required-CSP header.</title> 4 <title>Embedded Enforcement: Sec-Required-CSP header.</title> 5 <!-- 6 This test is creating and navigating several iframes. This can exceed the 7 "short" timeout". See https://crbug.com/1091896 8 --> 9 <meta name="timeout" content="long"> 5 10 <script src="/resources/testharness.js"></script> 6 11 <script src="/resources/testharnessreport.js"></script> … … 12 17 // CRLF characters 13 18 { "name": "\\r\\n character after directive name", 14 "csp": "s cript-src\r\n'unsafe-inline'",19 "csp": "style-src\r\n'unsafe-inline'", 15 20 "expected": null }, 16 21 { "name": "\\r\\n character in directive value", 17 "csp": "s cript-src 'unsafe-inline'\r\n'unsafe-eval'",22 "csp": "style-src 'unsafe-inline'\r\n'unsafe-eval'", 18 23 "expected": null }, 19 24 { "name": "\\n character after directive name", 20 "csp": "s cript-src\n'unsafe-inline'",25 "csp": "style-src\n'unsafe-inline'", 21 26 "expected": null }, 22 27 { "name": "\\n character in directive value", 23 "csp": "s cript-src 'unsafe-inline'\n'unsafe-eval'",28 "csp": "style-src 'unsafe-inline'\n'unsafe-eval'", 24 29 "expected": null }, 25 30 { "name": "\\r character after directive name", 26 "csp": "s cript-src\r'unsafe-inline'",31 "csp": "style-src\r'unsafe-inline'", 27 32 "expected": null }, 28 33 { "name": "\\r character in directive value", 29 "csp": "script-src 'unsafe-inline'\r'unsafe-eval'", 30 "expected": null }, 31 32 // HTML encoded CRLF characters 33 { "name": "%0D%0A character after directive name", 34 "csp": "script-src%0D%0A'unsafe-inline'", 35 "expected": null }, 36 { "name": "%0D%0A character in directive value", 37 "csp": "script-src 'unsafe-inline'%0D%0A'unsafe-eval'", 38 "expected": null }, 39 { "name": "%0A character after directive name", 40 "csp": "script-src%0A'unsafe-inline'", 41 "expected": null }, 42 { "name": "%0A character in directive value", 43 "csp": "script-src 'unsafe-inline'%0A'unsafe-eval'", 44 "expected": null }, 45 { "name": "%0D character after directive name", 46 "csp": "script-src%0D'unsafe-inline'", 47 "expected": null }, 48 { "name": "%0D character in directive value", 49 "csp": "script-src 'unsafe-inline'%0D'unsafe-eval'", 34 "csp": "style-src 'unsafe-inline'\r'unsafe-eval'", 50 35 "expected": null }, 51 36 52 37 // Attempt HTTP Header injection 53 38 { "name": "Attempt injecting after directive name using \\r\\n", 54 "csp": "s cript-src\r\nTest-Header-Injection: dummy",39 "csp": "style-src\r\nTest-Header-Injection: dummy", 55 40 "expected": null }, 56 41 { "name": "Attempt injecting after directive name using \\r", 57 "csp": "s cript-src\rTest-Header-Injection: dummy",42 "csp": "style-src\rTest-Header-Injection: dummy", 58 43 "expected": null }, 59 44 { "name": "Attempt injecting after directive name using \\n", 60 "csp": "s cript-src\nTest-Header-Injection: dummy",45 "csp": "style-src\nTest-Header-Injection: dummy", 61 46 "expected": null }, 62 47 63 48 { "name": "Attempt injecting after directive value using \\r\\n", 64 "csp": "s cript-src example.com\r\nTest-Header-Injection: dummy",49 "csp": "style-src example.com\r\nTest-Header-Injection: dummy", 65 50 "expected": null }, 66 51 { "name": "Attempt injecting after directive value using \\r", 67 "csp": "s cript-src example.com\rTest-Header-Injection: dummy",52 "csp": "style-src example.com\rTest-Header-Injection: dummy", 68 53 "expected": null }, 69 54 { "name": "Attempt injecting after directive value using \\n", 70 "csp": "s cript-src example.com\nTest-Header-Injection: dummy",55 "csp": "style-src example.com\nTest-Header-Injection: dummy", 71 56 "expected": null }, 72 57 73 58 { "name": "Attempt injecting after semicolon using \\r\\n", 74 "csp": "s cript-src example.com;\r\nTest-Header-Injection: dummy",59 "csp": "style-src example.com;\r\nTest-Header-Injection: dummy", 75 60 "expected": null }, 76 61 { "name": "Attempt injecting after semicolon using \\r", 77 "csp": "s cript-src example.com;\rTest-Header-Injection: dummy",62 "csp": "style-src example.com;\rTest-Header-Injection: dummy", 78 63 "expected": null }, 79 64 { "name": "Attempt injecting after semicolon using \\n", 80 "csp": "s cript-src example.com;\nTest-Header-Injection: dummy",65 "csp": "style-src example.com;\nTest-Header-Injection: dummy", 81 66 "expected": null }, 82 67 83 68 { "name": "Attempt injecting after space between name and value using \\r\\n", 84 "csp": "s cript-src \r\nTest-Header-Injection: dummy",69 "csp": "style-src \r\nTest-Header-Injection: dummy", 85 70 "expected": null }, 86 71 { "name": "Attempt injecting after space between name and value using \\r", 87 "csp": "s cript-src \rTest-Header-Injection: dummy",72 "csp": "style-src \rTest-Header-Injection: dummy", 88 73 "expected": null }, 89 74 { "name": "Attempt injecting after space between name and value using \\n", 90 "csp": "s cript-src \nTest-Header-Injection: dummy",75 "csp": "style-src \nTest-Header-Injection: dummy", 91 76 "expected": null }, 92 93 // Attempt HTTP Header injection using URL encoded characters94 { "name": "Attempt injecting after directive name using %0D%0A",95 "csp": "script-src%0D%0ATest-Header-Injection: dummy",96 "expected": null },97 { "name": "Attempt injecting after directive name using %0D",98 "csp": "script-src%0DTest-Header-Injection: dummy",99 "expected": null },100 { "name": "Attempt injecting after directive name using %0A",101 "csp": "script-src%0ATest-Header-Injection: dummy",102 "expected": null },103 104 { "name": "Attempt injecting after directive value using %0D%0A",105 "csp": "script-src example.com%0D%0ATest-Header-Injection: dummy",106 "expected": null },107 { "name": "Attempt injecting after directive value using %0D",108 "csp": "script-src example.com%0DTest-Header-Injection: dummy",109 "expected": null },110 { "name": "Attempt injecting after directive value using %0A",111 "csp": "script-src example.com%0ATest-Header-Injection: dummy",112 "expected": null },113 114 { "name": "Attempt injecting after semicolon using %0D%0A",115 "csp": "script-src example.com;%0D%0ATest-Header-Injection: dummy",116 "expected": null },117 { "name": "Attempt injecting after semicolon using %0D",118 "csp": "script-src example.com;%0DTest-Header-Injection: dummy",119 "expected": null },120 { "name": "Attempt injecting after semicolon using %0A",121 "csp": "script-src example.com;%0ATest-Header-Injection: dummy",122 "expected": null },123 124 { "name": "Attempt injecting after space between name and value using %0D%0A",125 "csp": "script-src %0D%0ATest-Header-Injection: dummy",126 "expected": null },127 { "name": "Attempt injecting after space between name and value using %0D",128 "csp": "script-src %0DTest-Header-Injection: dummy",129 "expected": null },130 { "name": "Attempt injecting after space between name and value using %0A",131 "csp": "script-src %0ATest-Header-Injection: dummy",132 "expected": null },133 134 77 ]; 135 78 -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/required_csp-header.html
r263605 r279838 25 25 "csp": "script-src 'unsafe-inline'", 26 26 "expected": "script-src 'unsafe-inline'" }, 27 { "name": "Wrong value of `csp` should nottrigger sending Sec-Required-CSP Header - gibberish csp",27 { "name": "Wrong but allowed value of `csp` should still trigger sending Sec-Required-CSP Header - gibberish csp", 28 28 "csp": "completely wrong csp", 29 "expected": "completely wrong csp" }, 30 { "name": "Wrong but allowed value of `csp` should still trigger sending Sec-Required-CSP Header - unknown policy name", 31 "csp": "invalid-policy-name http://example.com", 32 "expected": "invalid-policy-name http://example.com" }, 33 { "name": "Wrong but allowed value of `csp` should still trigger sending Sec-Required-CSP Header - unknown policy name in multiple directives", 34 "csp": "media-src http://example.com; invalid-policy-name http://example.com", 35 "expected": "media-src http://example.com; invalid-policy-name http://example.com" }, 36 { "name": "Wrong but allowed value of `csp` should still trigger sending Sec-Required-CSP Header - misspeled 'none'", 37 "csp": "media-src 'non'", 38 "expected": "media-src 'non'" }, 39 { "name": "Wrong but allowed value of `csp` should still trigger sending Sec-Required-CSP Header - query values in path", 40 "csp": "script-src 'unsafe-inline' 127.0.0.1:8000/path?query=string", 41 "expected": "script-src 'unsafe-inline' 127.0.0.1:8000/path?query=string" }, 42 { "name": "Wrong but allowed value of `csp` should still trigger sending Sec-Required-CSP Header - missing semicolon", 43 "csp": "script-src 'unsafe-inline' 'self' object-src 'self' style-src *", 44 "expected": "script-src 'unsafe-inline' 'self' object-src 'self' style-src *" }, 45 { "name": "Wrong and dangerous value of `csp` should not trigger sending Sec-Required-CSP Header - comma separated", 46 "csp": "script-src 'unsafe-inline' 'self', object-src 'none'", 29 47 "expected": null }, 30 { "name": "Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - unknown policy name", 31 "csp": "invalid-policy-name http://example.com", 48 { "name": "Wrong and dangerous value of `csp` should not trigger sending Sec-Required-CSP Header - invalid characters in directive names", 49 // script-src 127.0.0.1:8000 50 "csp": "script-src 'unsafe-inline' 127.0.0.1:8000", 32 51 "expected": null }, 33 { "name": "Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - unknown policy name in multiple directives", 34 "csp": "default-src http://example.com; invalid-policy-name http://example.com", 52 { "name": "Wrong and dangerous value of `csp` should not trigger sending Sec-Required-CSP Header - invalid character in directive name", 53 // script-src 127.0.0.1:8000 54 "csp": "media-src%20127.0.0.1%3A8000", 35 55 "expected": null }, 36 { "name": "Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - misspeled 'none'", 37 "csp": "default-src 'non'", 38 "expected": null }, 39 { "name": "Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - query values in path", 40 "csp": "script-src 127.0.0.1:8000/path?query=string", 41 "expected": null }, 42 { "name": "Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - missing semicolon", 43 "csp": "script-src 'self' object-src 'self' style-src *", 44 "expected": null }, 45 { "name": "Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - comma separated", 46 "csp": "script-src 'none', object-src 'none'", 47 "expected": null }, 48 { "name": "Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - html encoded string", 49 // script-src 127.0.0.1:8000 50 "csp": "script-src 127.0.0.1:8000", 51 "expected": null }, 52 { "name": "Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - url encoded string", 53 // script-src 127.0.0.1:8000 54 "csp": "script-src%20127.0.0.1%3A8000", 55 "expected": null }, 56 { "name": "Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - report-uri present", 56 { "name": "Wrong and dangerous value of `csp` should not trigger sending Sec-Required-CSP Header - report-uri present", 57 57 "csp": "script-src 'unsafe-inline'; report-uri resources/dummy-report.php", 58 58 "expected": null }, 59 { "name": "Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - report-to present",59 { "name": "Wrong and dangerous value of `csp` should not trigger sending Sec-Required-CSP Header - report-to present", 60 60 "csp": "script-src 'unsafe-inline'; report-to resources/dummy-report.php", 61 61 "expected": null }, -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-general.html
r263605 r279838 14 14 // return false negatives. 15 15 var tests = [ 16 { "name": "If there is no required csp, iframe should load.", 17 "required_csp": null, 16 { "name": "If there is no required csp, iframe should load.", 17 "required_csp": null, 18 18 "returned_csp": null, 19 19 "expected": IframeLoad.EXPECT_LOAD }, 20 { "name": "Iframe with empty returned CSP should be blocked.", 21 "required_csp": "style-src 'none';", 20 { "name": "Iframe with empty returned CSP should be blocked.", 21 "required_csp": "style-src 'none';", 22 22 "returned_csp": null, 23 23 "expected": IframeLoad.EXPECT_BLOCK }, 24 { "name": "Iframe with matching CSP should load.", 25 "required_csp": "style-src 'none'; script-src 'unsafe-inline'", 26 "returned_csp": "style-src 'none'; script-src 'unsafe-inline'", 24 { "name": "Iframe with matching CSP should load.", 25 "required_csp": "style-src 'none'; script-src 'unsafe-inline'", 26 "returned_csp": "style-src 'none'; script-src 'unsafe-inline'", 27 27 "expected": IframeLoad.EXPECT_LOAD }, 28 { "name": "Iframe with more restricting CSP should load.", 29 "required_csp": "script-src 'nonce-abc' 'nonce-123'", 30 "returned_csp": "script-src 'nonce-abc'", 28 { "name": "Iframe with more restricting CSP should load.", 29 "required_csp": "script-src 'nonce-abc' 'nonce-123'", 30 "returned_csp": "script-src 'nonce-abc'", 31 31 "expected": IframeLoad.EXPECT_LOAD }, 32 { "name": "Iframe with less restricting CSP should be blocked.", 33 "required_csp": "style-src 'none'; script-src 'none'", 34 "returned_csp": "style-src 'none'; script-src 'self' 'nonce-abc'", 32 { "name": "Iframe with less restricting CSP should be blocked.", 33 "required_csp": "style-src 'none'; script-src 'none'", 34 "returned_csp": "style-src 'none'; script-src 'self' 'nonce-abc'", 35 35 "expected": IframeLoad.EXPECT_BLOCK }, 36 { "name": "Iframe with a different CSP should be blocked.", 37 "required_csp": "script-src 'nonce-abc' 'nonce-123'", 38 "returned_csp": "style-src 'none'", 36 { "name": "Iframe with a different CSP should be blocked.", 37 "required_csp": "script-src 'nonce-abc' 'nonce-123'", 38 "returned_csp": "style-src 'none'", 39 39 "expected": IframeLoad.EXPECT_BLOCK }, 40 { "name": "Iframe with a matching and more restrictive ports should load.", 41 "required_csp": "frame-src http://c.com:443 http://b.com", 42 "returned_csp": "frame-src http://b.com:80 http://c.com:443", 40 { "name": "Iframe with a matching and more restrictive ports should load.", 41 "required_csp": "frame-src http://c.com:443 http://b.com", 42 "returned_csp": "frame-src http://b.com:80 http://c.com:443", 43 43 "expected": IframeLoad.EXPECT_LOAD }, 44 { "name": "Iframe should load even if the ports are different but are default for the protocols.", 45 "required_csp": "frame-src http://b.com:80", 46 "returned_csp": "child-src https://b.com:443", 44 { "name": "Host wildcard *.a.com does not match a.com", 45 "required_csp": "frame-src http://*.a.com", 46 "returned_csp": "frame-src http://a.com", 47 "expected": IframeLoad.EXPECT_BLOCK }, 48 { "name": "Host intersection with wildcards is computed correctly.", 49 "required_csp": "frame-sr 'none'", 50 "returned_csp": "frame-src http://a.com", 51 "returned_csp_2": "frame-src http://*.a.com", 47 52 "expected": IframeLoad.EXPECT_LOAD }, 53 { "name": "Iframe should load even if the ports are different but are default for the protocols.", 54 "required_csp": "frame-src http://b.com:80", 55 "returned_csp": "child-src https://b.com:443", 56 "expected": IframeLoad.EXPECT_LOAD }, 57 { "name": "Iframe should block if intersection allows sources which are not in required_csp.", 58 "required_csp": "style-src http://*.example.com:*", 59 "returned_csp": "style-src http://*.com:*", 60 "returned_csp_2": "style-src http://*.com http://*.example.com:*", 61 "expected": IframeLoad.EXPECT_BLOCK }, 62 { "name": "Iframe should block if intersection allows sources which are not in required_csp (other ordering).", 63 "required_csp": "style-src http://*.example.com:*", 64 "returned_csp": "style-src http://*.com:*", 65 "returned_csp_2": "style-src http://*.example.com:* http://*.com", 66 "expected": IframeLoad.EXPECT_BLOCK }, 67 { "name": "Iframe should load if intersection allows only sources which are in required_csp.", 68 "required_csp": "style-src http://*.example.com", 69 "returned_csp": "style-src http://*.example.com:*", 70 "returned_csp_2": "style-src http://*.com", 71 "expected": IframeLoad.EXPECT_LOAD }, 72 { "name": "Removed plugin-types directive should be ignored.", 73 "required_csp": "plugin-types application/pdf", 74 "returned_csp": null, 75 "expected": IframeLoad.EXPECT_LOAD }, 76 { "name": "Removed plugin-types directive should be ignored 2.", 77 "required_csp": "plugin-types application/pdf application/x-java-applet", 78 "returned_csp": "plugin-types application/pdf", 79 "expected": IframeLoad.EXPECT_LOAD }, 80 { "name": "Removed plugin-types directive should be ignored 3.", 81 "required_csp": "style-src 'none'; plugin-types application/pdf", 82 "returned_csp": null, 83 "expected": IframeLoad.EXPECT_BLOCK }, 48 84 ]; 49 85 … … 51 87 async_test(t => { 52 88 var url = generateUrlWithPolicies(Host.CROSS_ORIGIN, test.returned_csp); 89 if (test.returned_csp_2) 90 url.searchParams.append("policy2", test.returned_csp_2); 53 91 assert_iframe_with_csp(t, url, test.required_csp, test.expected, test.name, null); 54 92 }, test.name); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-hashes.html
r246330 r279838 10 10 <script> 11 11 var tests = [ 12 { "name": "'sha256-abc123' is properly subsumed.", 13 "required_csp": "style-src 'sha256-abc123'", 12 { "name": "'sha256-abc123' is properly subsumed.", 13 "required_csp": "style-src 'sha256-abc123'", 14 14 "returned_csp_1": "style-src 'sha256-abc123'", 15 15 "expected": IframeLoad.EXPECT_LOAD }, 16 { "name": "Returned should not include hashes not present in required csp.", 17 "required_csp": "style-src http://example.com", 16 { "name": "Returned should not include hashes not present in required csp.", 17 "required_csp": "style-src http://example.com", 18 18 "returned_csp_1": "style-src 'sha256-abc123'", 19 19 "expected": IframeLoad.EXPECT_BLOCK }, 20 { "name": "'sha256-abc123' is properly subsumed with other sources.", 21 "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-hashed-attributes' 'strict-dynamic' 'sha256-abc123'", 20 { "name": "'sha256-abc123' is properly subsumed with other sources.", 21 "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-hashed-attributes' 'strict-dynamic' 'sha256-abc123'", 22 22 "returned_csp_1": "style-src http://example1.com/foo/bar.html 'sha256-abc123'", 23 23 "expected": IframeLoad.EXPECT_LOAD }, 24 { "name": "Hashes do not have to be present in returned csp.", 25 "required_csp": "style-src http://example1.com/foo/ 'self' 'sha256-abc123'", 24 { "name": "Hashes do not have to be present in returned csp.", 25 "required_csp": "style-src http://example1.com/foo/ 'self' 'sha256-abc123'", 26 26 "returned_csp_1": "style-src http://example1.com/foo/", 27 27 "expected": IframeLoad.EXPECT_LOAD }, 28 { "name": "Hashes do not have to be present in returned csp but must not allow all inline behavior.", 29 "required_csp": "style-src http://example1.com/foo/ 'self' 'sha256-abc123'", 28 { "name": "Hashes do not have to be present in returned csp but must not allow all inline behavior.", 29 "required_csp": "style-src http://example1.com/foo/ 'self' 'sha256-abc123'", 30 30 "returned_csp_1": "style-src http://example1.com/foo/ 'unsafe-inline'", 31 31 "expected": IframeLoad.EXPECT_BLOCK }, 32 { "name": "Other expressions have to be subsumed.", 33 "required_csp": "style-src http://example1.com/foo/ 'self' 'sha256-abc123'", 32 { "name": "Other expressions have to be subsumed.", 33 "required_csp": "style-src http://example1.com/foo/ 'self' 'sha256-abc123'", 34 34 "returned_csp_1": "style-src http://example1.com/foo/ 'unsafe-eval' 'sha256-abc123'", 35 35 "expected": IframeLoad.EXPECT_BLOCK }, 36 { "name": "Other expressions have to be subsumed but 'unsafe-inline' gets ignored.", 37 "required_csp": "style-src http://example1.com/foo/ 'self' 'sha256-abc123'", 36 { "name": "Other expressions have to be subsumed but 'unsafe-inline' gets ignored.", 37 "required_csp": "style-src http://example1.com/foo/ 'self' 'sha256-abc123'", 38 38 "returned_csp_1": "style-src http://example1.com/foo/ 'unsafe-inline' 'sha256-abc123'", 39 39 "expected": IframeLoad.EXPECT_LOAD }, 40 { "name": "Effective policy is properly found.", 41 "required_csp": "style-src http://example1.com/foo/ 'self' 'sha256-abc123'", 40 { "name": "Effective policy is properly found.", 41 "required_csp": "style-src http://example1.com/foo/ 'self' 'sha256-abc123'", 42 42 "returned_csp_1": "style-src http://example1.com/foo/ 'unsafe-hashed-attributes' 'sha256-abc123'", 43 43 "returned_csp_2": "style-src http://example1.com/foo/ 'self' 'sha256-abc123'", 44 44 "expected": IframeLoad.EXPECT_LOAD }, 45 { "name": "Required csp must allow 'sha256-abc123'.", 46 "required_csp": "style-src http://example1.com/foo/ 'self'", 45 { "name": "Required csp must allow 'sha256-abc123'.", 46 "required_csp": "style-src http://example1.com/foo/ 'self'", 47 47 "returned_csp_1": "style-src http://example1.com/foo/ 'self' 'sha256-abc123'", 48 48 "expected": IframeLoad.EXPECT_BLOCK }, 49 { "name": "Effective policy is properly found where 'sha256-abc123' is not subsumed.", 50 "required_csp": "style-src http://example1.com/foo/ 'self'", 49 { "name": "Effective policy is properly found where 'sha256-abc123' is not subsumed.", 50 "required_csp": "style-src http://example1.com/foo/ 'self'", 51 51 "returned_csp_1": "style-src 'unsafe-hashed-attributes' 'sha256-abc123'", 52 52 "returned_csp_2": "style-src 'sha256-abc123' 'unsafe-inline'", 53 53 "expected": IframeLoad.EXPECT_BLOCK }, 54 { "name": "'sha256-abc123' is not subsumed by 'sha256-abc456'.", 55 "required_csp": "style-src http://example1.com/foo/ 'self' 'sha256-abc456'", 54 { "name": "'sha256-abc123' is not subsumed by 'sha256-abc456'.", 55 "required_csp": "style-src http://example1.com/foo/ 'self' 'sha256-abc456'", 56 56 "returned_csp_1": "style-src 'unsafe-hashed-attributes' 'sha256-abc123'", 57 57 "returned_csp_2": "style-src 'sha256-abc123' 'unsafe-inline'", 58 58 "expected": IframeLoad.EXPECT_BLOCK }, 59 { "name": "Effective policy now does not allow 'sha256-abc123'.", 60 "required_csp": "style-src http://example1.com/foo/ 'self' 'sha256-abc456'", 59 { "name": "Effective policy now does not allow 'sha256-abc123'.", 60 "required_csp": "style-src http://example1.com/foo/ 'self' 'sha256-abc456'", 61 61 "returned_csp_1": "style-src 'unsafe-hashed-attributes' 'sha256-abc123' 'sha256-abc456'", 62 62 "returned_csp_2": "style-src 'sha256-abc456' 'unsafe-inline'", 63 63 "expected": IframeLoad.EXPECT_LOAD }, 64 { "name": "Effective policy is properly found where 'sha256-abc123' is not part of it.", 65 "required_csp": "style-src http://example1.com/foo/ 'self'", 64 { "name": "Effective policy is properly found where 'sha256-abc123' is not part of it.", 65 "required_csp": "style-src http://example1.com/foo/ 'self'", 66 66 "returned_csp_1": "style-src 'unsafe-hashed-attributes' 'self'", 67 67 "returned_csp_2": "style-src 'sha256-abc123' 'self'", -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-host_sources-hosts.html
r246330 r279838 10 10 <script> 11 11 var tests = [ 12 { "name": "Host must match.", 13 "required_csp": "img-src http://c.com", 12 { "name": "Host must match.", 13 "required_csp": "img-src http://c.com", 14 14 "returned_csp": "img-src http://b.com", 15 15 "expected": IframeLoad.EXPECT_BLOCK }, 16 { "name": "Hosts without wildcards must match.", 17 "required_csp": "img-src http://c.com:* http://inner.b.com", 16 { "name": "Hosts without wildcards must match.", 17 "required_csp": "img-src http://c.com:* http://inner.b.com", 18 18 "returned_csp": "img-src http://b.com", 19 19 "expected": IframeLoad.EXPECT_BLOCK }, 20 { "name": "More specific subdomain should not match.", 21 "required_csp": "img-src http://c.com:* http://b.com", 20 { "name": "More specific subdomain should not match.", 21 "required_csp": "img-src http://c.com:* http://b.com", 22 22 "returned_csp": "img-src http://inner.b.com", 23 23 "expected": IframeLoad.EXPECT_BLOCK }, 24 { "name": "Specified host should not match a wildcard host.", 25 "required_csp": "img-src http://c.com:* http://inner.b.com", 24 { "name": "Specified host should not match a wildcard host.", 25 "required_csp": "img-src http://c.com:* http://inner.b.com", 26 26 "returned_csp": "img-src http://*.b.com", 27 27 "expected": IframeLoad.EXPECT_BLOCK }, 28 { "name": "A wildcard host should match a more specific host.", 29 "required_csp": "img-src http://c.com:* http://*.b.com", 28 { "name": "A wildcard host should match a more specific host.", 29 "required_csp": "img-src http://c.com:* http://*.b.com", 30 30 "returned_csp": "img-src https://inner.b.com", 31 31 "expected": IframeLoad.EXPECT_LOAD }, -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-host_sources-paths.html
r246330 r279838 10 10 <script> 11 11 var tests = [ 12 { "name": "Returned CSP must specify a path.", 13 "required_csp": "img-src http://c.com:* http://b.com/example.html", 14 "returned_csp": "img-src http://b.com", 12 { "name": "Returned CSP must specify a path.", 13 "required_csp": "img-src http://c.com:* http://b.com/example.html", 14 "returned_csp": "img-src http://b.com", 15 15 "expected": IframeLoad.EXPECT_BLOCK }, 16 { "name": "Returned CSP has a more specific path.", 17 "required_csp": "img-src http://c.com:* http://b.com", 18 "returned_csp": "img-src http://b.com/example.html", 16 { "name": "Returned CSP has a more specific path.", 17 "required_csp": "img-src http://c.com:* http://b.com", 18 "returned_csp": "img-src http://b.com/example.html", 19 19 "expected": IframeLoad.EXPECT_LOAD }, 20 { "name": "Matching paths.", 20 { "name": "Matching paths.", 21 21 "required_csp": "img-src http://c.com:* http://b.com/example.html", 22 22 "returned_csp": "img-src http://b.com/example.html", 23 23 "expected": IframeLoad.EXPECT_LOAD }, 24 { "name": "Empty path is not subsumed by specified paths.", 24 { "name": "Empty path is not subsumed by specified paths.", 25 25 "required_csp": "img-src http://b.com/page1.html http://b.com/page2.html http://b.com/page3.html", 26 26 "returned_csp": "img-src http://b.com/", 27 27 "expected": IframeLoad.EXPECT_BLOCK }, 28 { "name": "All specific paths match except the order.", 29 "required_csp": "img-src http://b.com/page1.html http://b.com/page2.html http://b.com/page3.html", 30 "returned_csp": "img-src http://b.com/page2.html http://b.com/page3.html http://b.com/page1.html", 28 { "name": "All specific paths match except the order.", 29 "required_csp": "img-src http://b.com/page1.html http://b.com/page2.html http://b.com/page3.html", 30 "returned_csp": "img-src http://b.com/page2.html http://b.com/page3.html http://b.com/page1.html", 31 31 "expected": IframeLoad.EXPECT_LOAD }, 32 { "name": "Returned CSP allows only one path.", 33 "required_csp": "img-src http://b.com/page1.html http://b.com/page2.html http://b.com/page3.html", 34 "returned_csp": "img-src http://b.com/page2.html", 32 { "name": "Returned CSP allows only one path.", 33 "required_csp": "img-src http://b.com/page1.html http://b.com/page2.html http://b.com/page3.html", 34 "returned_csp": "img-src http://b.com/page2.html", 35 35 "expected": IframeLoad.EXPECT_LOAD }, 36 { "name": "`/` path should be subsumed by an empty path.", 37 "required_csp": "img-src http://b.com", 38 "returned_csp": "img-src http://b.com/", 36 { "name": "`/` path should be subsumed by an empty path.", 37 "required_csp": "img-src http://b.com", 38 "returned_csp": "img-src http://b.com/", 39 39 "expected": IframeLoad.EXPECT_LOAD }, 40 { "name": "Unspecified path should be subsumed by `/`.", 41 "required_csp": "img-src http://b.com/", 42 "returned_csp": "img-src http://b.com", 40 { "name": "Unspecified path should be subsumed by `/`.", 41 "required_csp": "img-src http://b.com/", 42 "returned_csp": "img-src http://b.com", 43 43 "expected": IframeLoad.EXPECT_LOAD }, 44 { "name": "That should not be true when required csp specifies a specific page.", 45 "required_csp": "img-src http://b.com/path.html", 46 "returned_csp": "img-src http://b.com", 44 { "name": "That should not be true when required csp specifies a specific page.", 45 "required_csp": "img-src http://b.com/path.html", 46 "returned_csp": "img-src http://b.com", 47 47 "expected": IframeLoad.EXPECT_BLOCK }, 48 48 ]; -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-host_sources-ports.html
r246330 r279838 10 10 <script> 11 11 var tests = [ 12 { "name": "Specified ports must match.", 13 "required_csp": "img-src http://c.com:* http://b.com:80", 14 "returned_csp": "img-src http://b.com:36", 12 { "name": "Specified ports must match.", 13 "required_csp": "img-src http://c.com:* http://b.com:80", 14 "returned_csp": "img-src http://b.com:36", 15 15 "expected": IframeLoad.EXPECT_BLOCK }, 16 { "name": "Returned CSP should be subsumed even if the port is not specified but is a default port for a scheme.", 17 "required_csp": "img-src http://c.com:* http://b.com:80", 18 "returned_csp": "img-src http://b.com", 16 { "name": "Returned CSP should be subsumed even if the port is not specified but is a default port for a scheme.", 17 "required_csp": "img-src http://c.com:* http://b.com:80", 18 "returned_csp": "img-src http://b.com", 19 19 "expected": IframeLoad.EXPECT_LOAD }, 20 { "name": "Returned CSP should be subsumed even if the port is not specified but is a default port for a more secure scheme.", 21 "required_csp": "img-src http://c.com:* http://b.com:80", 22 "returned_csp": "img-src https://b.com", 20 { "name": "Returned CSP should be subsumed even if the port is not specified but is a default port for a more secure scheme.", 21 "required_csp": "img-src http://c.com:* http://b.com:80", 22 "returned_csp": "img-src https://b.com", 23 23 "expected": IframeLoad.EXPECT_LOAD }, 24 { "name": "The same should hold for `ws` case.", 25 "required_csp": "img-src http://c.com:* ws://b.com:80", 26 "returned_csp": "img-src wss://b.com", 24 { "name": "The same should hold for `ws` case.", 25 "required_csp": "img-src http://c.com:* ws://b.com:80", 26 "returned_csp": "img-src wss://b.com", 27 27 "expected": IframeLoad.EXPECT_LOAD }, 28 { "name": "Unspecified ports must match if schemes match.", 29 "required_csp": "img-src http://c.com:* http://b.com", 30 "returned_csp": "img-src https://b.com", 28 { "name": "Unspecified ports must match if schemes match.", 29 "required_csp": "img-src http://c.com:* http://b.com", 30 "returned_csp": "img-src https://b.com", 31 31 "expected": IframeLoad.EXPECT_LOAD }, 32 { "name": "Returned CSP should be subsumed if the port is specified.", 33 "required_csp": "img-src http://c.com:* http://b.com", 34 "returned_csp": "img-src http://b.com:80", 32 { "name": "Returned CSP should be subsumed if the port is specified.", 33 "required_csp": "img-src http://c.com:* http://b.com", 34 "returned_csp": "img-src http://b.com:80", 35 35 "expected": IframeLoad.EXPECT_LOAD }, 36 { "name": "Returned CSP should be subsumed if the port is specified but the scheme is more secure.", 37 "required_csp": "img-src http://c.com:* http://b.com", 38 "returned_csp": "img-src https://b.com:443", 36 { "name": "Returned CSP should be subsumed if the port is specified but the scheme is more secure.", 37 "required_csp": "img-src http://c.com:* http://b.com", 38 "returned_csp": "img-src https://b.com:443", 39 39 "expected": IframeLoad.EXPECT_LOAD }, 40 { "name": "Returned CSP should be subsumed if the port is specified but is not default for a more secure scheme.", 41 "required_csp": "img-src http://c.com:* http://b.com", 42 "returned_csp": "img-src https://b.com:36", 40 { "name": "Returned CSP should be subsumed if the port is specified but is not default for a more secure scheme.", 41 "required_csp": "img-src http://c.com:* http://b.com", 42 "returned_csp": "img-src https://b.com:36", 43 43 "expected": IframeLoad.EXPECT_BLOCK }, 44 { "name": "Returned CSP should be subsumed if the ports match but schemes are not identical.", 45 "required_csp": "img-src http://c.com:* http://b.com:36", 46 "returned_csp": "img-src https://b.com:36", 44 { "name": "Returned CSP should be subsumed if the ports match but schemes are not identical.", 45 "required_csp": "img-src http://c.com:* http://b.com:36", 46 "returned_csp": "img-src https://b.com:36", 47 47 "expected": IframeLoad.EXPECT_LOAD }, 48 { "name": "Returned CSP should be subsumed if the ports match but schemes are not identical for `ws`.", 49 "required_csp": "img-src http://c.com:* ws://b.com:36", 50 "returned_csp": "img-src wss://b.com:36", 48 { "name": "Returned CSP should be subsumed if the ports match but schemes are not identical for `ws`.", 49 "required_csp": "img-src http://c.com:* ws://b.com:36", 50 "returned_csp": "img-src wss://b.com:36", 51 51 "expected": IframeLoad.EXPECT_LOAD }, 52 { "name": "Wildcard port should match unspecified port.", 53 "required_csp": "img-src http://c.com:* ws://b.com:*", 54 "returned_csp": "img-src wss://b.com", 52 { "name": "Wildcard port should match unspecified port.", 53 "required_csp": "img-src http://c.com:* ws://b.com:*", 54 "returned_csp": "img-src wss://b.com", 55 55 "expected": IframeLoad.EXPECT_LOAD }, 56 { "name": "Wildcard port should match any specific port.", 57 "required_csp": "img-src http://c.com:* ws://b.com:*", 58 "returned_csp": "img-src wss://b.com:36", 56 { "name": "Wildcard port should match any specific port.", 57 "required_csp": "img-src http://c.com:* ws://b.com:*", 58 "returned_csp": "img-src wss://b.com:36", 59 59 "expected": IframeLoad.EXPECT_LOAD }, 60 { "name": "Wildcard port should match a wildcard.", 61 "required_csp": "img-src http://c.com:* ws://b.com:*", 62 "returned_csp": "img-src wss://b.com:*", 60 { "name": "Wildcard port should match a wildcard.", 61 "required_csp": "img-src http://c.com:* ws://b.com:*", 62 "returned_csp": "img-src wss://b.com:*", 63 63 "expected": IframeLoad.EXPECT_LOAD }, 64 { "name": "Wildcard port should not be subsumed by a default port.", 65 "required_csp": "img-src http://c.com:* ws://b.com", 66 "returned_csp": "img-src ws://b.com:*", 64 { "name": "Wildcard port should not be subsumed by a default port.", 65 "required_csp": "img-src http://c.com:* ws://b.com", 66 "returned_csp": "img-src ws://b.com:*", 67 67 "expected": IframeLoad.EXPECT_BLOCK }, 68 { "name": "Wildcard port should not be subsumed by a spcified port.", 69 "required_csp": "img-src http://c.com:* ws://b.com:80", 70 "returned_csp": "img-src ws://b.com:*", 68 { "name": "Wildcard port should not be subsumed by a spcified port.", 69 "required_csp": "img-src http://c.com:* ws://b.com:80", 70 "returned_csp": "img-src ws://b.com:*", 71 71 "expected": IframeLoad.EXPECT_BLOCK }, 72 72 ]; -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-host_sources-protocols.html
r246330 r279838 10 10 <script> 11 11 var tests = [ 12 { "name": "`https` is more restrictive than `http`.", 13 "required_csp": "img-src http://c.com:* https://b.com", 12 { "name": "`https` is more restrictive than `http`.", 13 "required_csp": "img-src http://c.com:* https://b.com", 14 14 "returned_csp": "img-src http://b.com", 15 15 "expected": IframeLoad.EXPECT_BLOCK }, 16 { "name": "The reverse allows iframe be to be loaded.", 17 "required_csp": "img-src http://c.com:* http://b.com", 16 { "name": "The reverse allows iframe be to be loaded.", 17 "required_csp": "img-src http://c.com:* http://b.com", 18 18 "returned_csp": "img-src https://b.com", 19 19 "expected": IframeLoad.EXPECT_LOAD }, 20 { "name": "Matching `https` protocols.", 21 "required_csp": "img-src http://c.com:* https://b.com", 22 "returned_csp": "img-src https://b.com", 20 { "name": "Matching `https` protocols.", 21 "required_csp": "img-src http://c.com:* https://b.com", 22 "returned_csp": "img-src https://b.com", 23 23 "expected": IframeLoad.EXPECT_LOAD }, 24 { "name": "`http:` should subsume all host source expressions with this protocol.", 25 "required_csp": "img-src http:", 26 "returned_csp": "img-src http://c.com:* https://b.com http://c.com", 24 { "name": "`http:` should subsume all host source expressions with this protocol.", 25 "required_csp": "img-src http:", 26 "returned_csp": "img-src http://c.com:* https://b.com http://c.com", 27 27 "expected": IframeLoad.EXPECT_LOAD }, 28 { "name": "`http:` should subsume all host source expressions with `https:`.", 29 "required_csp": "img-src http:", 30 "returned_csp": "img-src https://c.com:* https://b.com http://c.com", 28 { "name": "`http:` should subsume all host source expressions with `https:`.", 29 "required_csp": "img-src http:", 30 "returned_csp": "img-src https://c.com:* https://b.com http://c.com", 31 31 "expected": IframeLoad.EXPECT_LOAD }, 32 { "name": "`http:` does not subsume other protocols.", 33 "required_csp": "img-src http:", 34 "returned_csp": "img-src https://c.com:* wss://b.com http://c.com", 32 { "name": "`http:` does not subsume other protocols.", 33 "required_csp": "img-src http:", 34 "returned_csp": "img-src https://c.com:* wss://b.com http://c.com", 35 35 "expected": IframeLoad.EXPECT_BLOCK }, 36 { "name": "If scheme source is present in returned csp, it must be specified in required csp too.", 37 "required_csp": "img-src https://c.com:* wss://b.com http://c.com", 38 "returned_csp": "img-src http:", 36 { "name": "If scheme source is present in returned csp, it must be specified in required csp too.", 37 "required_csp": "img-src https://c.com:* wss://b.com http://c.com", 38 "returned_csp": "img-src http:", 39 39 "expected": IframeLoad.EXPECT_BLOCK }, 40 { "name": "`http:` subsumes other `http:` source expression.", 41 "required_csp": "img-src http:", 42 "returned_csp": "img-src http: https://c.com:* https://b.com http://c.com", 40 { "name": "`http:` subsumes other `http:` source expression.", 41 "required_csp": "img-src http:", 42 "returned_csp": "img-src http: https://c.com:* https://b.com http://c.com", 43 43 "expected": IframeLoad.EXPECT_LOAD }, 44 { "name": "`http:` subsumes other `https:` source expression and expressions with `http:`.", 45 "required_csp": "img-src http:", 46 "returned_csp": "img-src https: https://c.com:* http://b.com", 44 { "name": "`http:` subsumes other `https:` source expression and expressions with `http:`.", 45 "required_csp": "img-src http:", 46 "returned_csp": "img-src https: https://c.com:* http://b.com", 47 47 "expected": IframeLoad.EXPECT_LOAD }, 48 { "name": "All scheme sources must be subsumed.", 49 "required_csp": "img-src http: wss:", 50 "returned_csp": "img-src https: ws:", 48 { "name": "All scheme sources must be subsumed.", 49 "required_csp": "img-src http: wss:", 50 "returned_csp": "img-src https: ws:", 51 51 "expected": IframeLoad.EXPECT_BLOCK }, 52 { "name": "All scheme sources are subsumed by their stronger variants.", 53 "required_csp": "img-src http: wss:", 54 "returned_csp": "img-src https: wss:", 52 { "name": "All scheme sources are subsumed by their stronger variants.", 53 "required_csp": "img-src http: wss:", 54 "returned_csp": "img-src https: wss:", 55 55 "expected": IframeLoad.EXPECT_LOAD }, 56 56 ]; -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-none.html
r246330 r279838 10 10 <script> 11 11 var tests = [ 12 { "name": "Empty required csp subsumes empty list of returned policies.", 13 "required_csp": "", 12 { "name": "Empty required csp subsumes empty list of returned policies.", 13 "required_csp": "", 14 14 "returned_csp_1": "", 15 15 "returned_csp_2": null, 16 16 "expected": IframeLoad.EXPECT_LOAD }, 17 { "name": "Empty required csp subsumes any list of policies.", 18 "required_csp": "", 17 { "name": "Empty required csp subsumes any list of policies.", 18 "required_csp": "", 19 19 "returned_csp_1": "img-src http://example.com", 20 20 "returned_csp_2": null, 21 21 "expected": IframeLoad.EXPECT_LOAD }, 22 { "name": "Empty required csp subsumes a policy with `none`.", 23 "required_csp": "", 22 { "name": "Empty required csp subsumes a policy with `none`.", 23 "required_csp": "", 24 24 "returned_csp_1": "img-src 'none'", 25 25 "returned_csp_2": null, 26 26 "expected": IframeLoad.EXPECT_LOAD }, 27 { "name": "Required policy that allows `none` does not subsume empty list of policies.", 28 "required_csp": "img-src ", 27 { "name": "Required policy that allows `none` does not subsume empty list of policies.", 28 "required_csp": "img-src ", 29 29 "returned_csp_1": "", 30 30 "returned_csp_2": null, 31 31 "expected": IframeLoad.EXPECT_BLOCK }, 32 { "name": "Required csp with effective `none` does not subsume a host source expression.", 33 "required_csp": "img-src ", 32 { "name": "Required csp with effective `none` does not subsume a host source expression.", 33 "required_csp": "img-src ", 34 34 "returned_csp_1": "img-src http://example.com", 35 35 "returned_csp_2": null, 36 36 "expected": IframeLoad.EXPECT_BLOCK }, 37 { "name": "Required csp with `none` does not subsume a host source expression.", 38 "required_csp": "img-src 'none'", 37 { "name": "Required csp with `none` does not subsume a host source expression.", 38 "required_csp": "img-src 'none'", 39 39 "returned_csp_1": "img-src http://example.com", 40 40 "returned_csp_2": null, 41 41 "expected": IframeLoad.EXPECT_BLOCK }, 42 { "name": "Required csp with effective `none` does not subsume `none` of another directive.", 43 "required_csp": "img-src ", 42 { "name": "Required csp with effective `none` does not subsume `none` of another directive.", 43 "required_csp": "img-src ", 44 44 "returned_csp_1": "frame-src 'none'", 45 45 "returned_csp_2": null, 46 46 "expected": IframeLoad.EXPECT_BLOCK }, 47 { "name": "Required csp with `none` does not subsume `none` of another directive.", 48 "required_csp": "img-src 'none'", 47 { "name": "Required csp with `none` does not subsume `none` of another directive.", 48 "required_csp": "img-src 'none'", 49 49 "returned_csp_1": "frame-src 'none'", 50 50 "returned_csp_2": null, 51 51 "expected": IframeLoad.EXPECT_BLOCK }, 52 { "name": "Required csp with `none` does not subsume `none` of different directives.", 53 "required_csp": "img-src ", 52 { "name": "Required csp with `none` does not subsume `none` of different directives.", 53 "required_csp": "img-src ", 54 54 "returned_csp_1": "img-src http://*.one.com", 55 55 "returned_csp_2": "frame-src https://two.com", 56 56 "expected": IframeLoad.EXPECT_BLOCK }, 57 { "name": "Required csp with `none` subsumes effective list of `none`.", 58 "required_csp": "img-src ", 57 { "name": "Required csp with `none` subsumes effective list of `none`.", 58 "required_csp": "img-src ", 59 59 "returned_csp_1": "img-src http://*.one.com", 60 60 "returned_csp_2": "img-src https://two.com", 61 61 "expected": IframeLoad.EXPECT_LOAD }, 62 { "name": "Required csp with `none` subsumes effective list of `none` despite other keywords.", 63 "required_csp": "img-src 'none'", 62 { "name": "Required csp with `none` subsumes effective list of `none` despite other keywords.", 63 "required_csp": "img-src 'none'", 64 64 "returned_csp_1": "img-src http://*.one.com", 65 65 "returned_csp_2": "img-src 'self'", 66 66 "expected": IframeLoad.EXPECT_LOAD }, 67 { "name": "Source list with exprssions other than `none` make `none` ineffective.", 68 "required_csp": "img-src http://example.com 'none'", 67 { "name": "Source list with exprssions other than `none` make `none` ineffective.", 68 "required_csp": "img-src http://example.com 'none'", 69 69 "returned_csp_1": "img-src http://example.com", 70 70 "returned_csp_2": null, 71 71 "expected": IframeLoad.EXPECT_LOAD }, 72 { "name": "Returned csp with `none` is subsumed by any required csp.", 73 "required_csp": "img-src http://example.com", 72 { "name": "Returned csp with `none` is subsumed by any required csp.", 73 "required_csp": "img-src http://example.com", 74 74 "returned_csp_1": "img-src 'none'", 75 75 "returned_csp_2": null, 76 76 "expected": IframeLoad.EXPECT_LOAD }, 77 { "name": "Returned csp with effective `none` is subsumed by any required csp.", 78 "required_csp": "img-src http://example.com", 77 { "name": "Returned csp with effective `none` is subsumed by any required csp.", 78 "required_csp": "img-src http://example.com", 79 79 "returned_csp_1": "img-src http://example.com", 80 80 "returned_csp_2": "img-src http://non-example.com", 81 81 "expected": IframeLoad.EXPECT_LOAD }, 82 { "name": "Both required and returned csp are `none`.", 83 "required_csp": "img-src 'none'", 82 { "name": "Both required and returned csp are `none`.", 83 "required_csp": "img-src 'none'", 84 84 "returned_csp_1": "img-src 'none'", 85 85 "returned_csp_2": "img-src http://non-example.com", 86 86 "expected": IframeLoad.EXPECT_LOAD }, 87 { "name": "Both required and returned csp are `none` for only one directive.", 88 "required_csp": "default-src 'none'", 87 { "name": "Both required and returned csp are `none` for only one directive.", 88 "required_csp": "default-src 'none'", 89 89 "returned_csp_1": "img-src 'none'", 90 90 "returned_csp_2": "script-src 'unsafe-inline'", 91 91 "expected": IframeLoad.EXPECT_BLOCK }, 92 { "name": "Both required and returned csp are empty.", 93 "required_csp": "img-src ", 92 { "name": "Both required and returned csp are empty.", 93 "required_csp": "img-src ", 94 94 "returned_csp_1": "img-src ", 95 95 "returned_csp_2": null, 96 96 "expected": IframeLoad.EXPECT_LOAD }, 97 { "name": "Both required and returned csp are effectively 'none'.", 98 "required_csp": "img-src ", 97 { "name": "Both required and returned csp are effectively 'none'.", 98 "required_csp": "img-src ", 99 99 "returned_csp_1": "img-src http://a.com", 100 100 "returned_csp_2": "img-src http://b.com", -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-self.html
r246330 r279838 10 10 <script> 11 11 var tests = [ 12 { "name": "'self' keywords should match.", 13 "required_csp": "img-src 'self' http://b.com:*", 12 { "name": "'self' keywords should match.", 13 "required_csp": "img-src 'self' http://b.com:*", 14 14 "returned_csp": "img-src 'self' http://b.com:*", 15 15 "expected": IframeLoad.EXPECT_LOAD }, 16 { "name": "Returned CSP does not have to specify 'self'.", 17 "required_csp": "img-src 'self' http://b.com:*", 16 { "name": "Returned CSP does not have to specify 'self'.", 17 "required_csp": "img-src 'self' http://b.com:*", 18 18 "returned_csp": "img-src http://b.com:*", 19 19 "expected": IframeLoad.EXPECT_LOAD }, 20 { "name": "Returned CSP must not allow 'self' if required CSP does not.", 21 "required_csp": "img-src http://b.com:*", 20 { "name": "Returned CSP must not allow 'self' if required CSP does not.", 21 "required_csp": "img-src http://b.com:*", 22 22 "returned_csp": "img-src 'self' http://b.com:*", 23 23 "expected": IframeLoad.EXPECT_BLOCK }, 24 { "name": "Returned 'self' should match to an origin's url.", 25 "required_csp": "img-src 'self' http://b.com:*", 24 { "name": "Returned 'self' should match to an origin's url.", 25 "required_csp": "img-src 'self' http://b.com:*", 26 26 "returned_csp": "img-src " + getCrossOrigin(), 27 27 "expected": IframeLoad.EXPECT_LOAD }, 28 { "name": "Required 'self' should match to a origin's url.", 29 "required_csp": "img-src " + getCrossOrigin() + " http://b.com:*", 28 { "name": "Required 'self' should match to a origin's url.", 29 "required_csp": "img-src " + getCrossOrigin() + " http://b.com:*", 30 30 "returned_csp": "img-src 'self'", 31 31 "expected": IframeLoad.EXPECT_LOAD }, 32 { "name": "Required 'self' should subsume a more secure version of origin's url.", 33 "required_csp": "img-src 'self' http://b.com:*", 32 { "name": "Required 'self' should subsume a more secure version of origin's url.", 33 "required_csp": "img-src 'self' http://b.com:*", 34 34 "returned_csp": "img-src " + getSecureCrossOrigin(), 35 35 "expected": IframeLoad.EXPECT_LOAD }, 36 { "name": "Returned 'self' should not be subsumed by a more secure version of origin's url.", 37 "required_csp": "img-src " + getSecureCrossOrigin() + " http://b.com:*", 36 { "name": "Returned 'self' should not be subsumed by a more secure version of origin's url.", 37 "required_csp": "img-src " + getSecureCrossOrigin() + " http://b.com:*", 38 38 "returned_csp": "img-src 'self'", 39 39 "expected": IframeLoad.EXPECT_BLOCK }, -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-strict_dynamic.html
r263605 r279838 14 14 // support/echo-policy-multiple.py), otherwise the test might 15 15 // return false negatives. 16 { "name": "'strict-dynamic' is ineffective for `style-src`.", 17 "required_csp": "style-src http://example1.com/foo/ 'self'", 16 { "name": "'strict-dynamic' is ineffective for `style-src`.", 17 "required_csp": "style-src http://example1.com/foo/ 'self'", 18 18 "returned_csp_1": "style-src 'strict-dynamic' http://example1.com/foo/bar.html", 19 19 "expected": IframeLoad.EXPECT_LOAD }, 20 { "name": "'strict-dynamic' is ineffective for `img-src`.", 21 "required_csp": "img-src http://example1.com/foo/ 'self'", 20 { "name": "'strict-dynamic' is ineffective for `img-src`.", 21 "required_csp": "img-src http://example1.com/foo/ 'self'", 22 22 "returned_csp_1": "img-src 'strict-dynamic' http://example1.com/foo/bar.html", 23 23 "expected": IframeLoad.EXPECT_LOAD }, 24 { "name": "'strict-dynamic' is ineffective for `frame-src`.", 25 "required_csp": "frame-src http://example1.com/foo/ 'self'", 24 { "name": "'strict-dynamic' is ineffective for `frame-src`.", 25 "required_csp": "frame-src http://example1.com/foo/ 'self'", 26 26 "returned_csp_1": "frame-src 'strict-dynamic' http://example1.com/foo/bar.html", 27 27 "expected": IframeLoad.EXPECT_LOAD }, 28 { "name": "'strict-dynamic' is ineffective for `child-src`.", 29 "required_csp": "child-src http://example1.com/foo/ 'self'", 28 { "name": "'strict-dynamic' is ineffective for `child-src`.", 29 "required_csp": "child-src http://example1.com/foo/ 'self'", 30 30 "returned_csp_1": "child-src 'strict-dynamic' http://example1.com/foo/bar.html", 31 31 "expected": IframeLoad.EXPECT_LOAD }, 32 { "name": "'strict-dynamic' is effective only for `script-src`.", 33 "required_csp": "script-src http://example1.com/foo/ 'self'", 32 { "name": "'strict-dynamic' is effective only for `script-src`.", 33 "required_csp": "script-src http://example1.com/foo/ 'self'", 34 34 "returned_csp_1": "script-src 'strict-dynamic' http://example1.com/foo/bar.html 'nonce-abc'", 35 35 "expected": IframeLoad.EXPECT_BLOCK }, 36 36 { "name": "'strict-dynamic' is properly handled for finding effective policy.", 37 "required_csp": "script-src http://example1.com/foo/ 'self'", 37 "required_csp": "script-src http://example1.com/foo/ 'self'", 38 38 "returned_csp_1": "script-src 'strict-dynamic' http://example1.com/foo/bar.html 'nonce-abc'", 39 39 "returned_csp_2": "script-src 'strict-dynamic' 'nonce-abc'", 40 40 "expected": IframeLoad.EXPECT_BLOCK }, 41 { "name": "'strict-dynamic' makes host source expressions ineffective.", 42 "required_csp": "script-src 'strict-dynamic' 'nonce-abc'", 41 { "name": "'strict-dynamic' makes host source expressions ineffective.", 42 "required_csp": "script-src 'strict-dynamic' 'nonce-abc'", 43 43 "returned_csp_1": "script-src http://example.com 'strict-dynamic' 'nonce-abc'", 44 44 "expected": IframeLoad.EXPECT_LOAD }, 45 { "name": "'strict-dynamic' makes scheme source expressions ineffective.", 46 "required_csp": "script-src 'strict-dynamic' 'nonce-abc'", 45 { "name": "'strict-dynamic' makes scheme source expressions ineffective.", 46 "required_csp": "script-src 'strict-dynamic' 'nonce-abc'", 47 47 "returned_csp_1": "script-src http: 'strict-dynamic' 'nonce-abc'", 48 48 "expected": IframeLoad.EXPECT_LOAD }, 49 { "name": "'strict-dynamic' makes 'self' ineffective.", 50 "required_csp": "script-src 'strict-dynamic' 'nonce-abc'", 49 { "name": "'strict-dynamic' makes 'self' ineffective.", 50 "required_csp": "script-src 'strict-dynamic' 'nonce-abc'", 51 51 "returned_csp_1": "script-src 'self' 'strict-dynamic' 'nonce-abc'", 52 52 "expected": IframeLoad.EXPECT_LOAD }, 53 { "name": "'strict-dynamic' makes 'unsafe-inline' ineffective.", 54 "required_csp": "script-src 'strict-dynamic' 'nonce-abc'", 53 { "name": "'strict-dynamic' makes 'unsafe-inline' ineffective.", 54 "required_csp": "script-src 'strict-dynamic' 'nonce-abc'", 55 55 "returned_csp_1": "script-src 'unsafe-inline' 'strict-dynamic' 'nonce-abc'", 56 56 "expected": IframeLoad.EXPECT_LOAD }, 57 { "name": "'strict-dynamic' has to be allowed by required csp if it is present in returned csp.", 58 "required_csp": "script-src 'nonce-abc'", 57 { "name": "'strict-dynamic' has to be allowed by required csp if it is present in returned csp.", 58 "required_csp": "script-src 'nonce-abc'", 59 59 "returned_csp_1": "script-src 'strict-dynamic' 'nonce-abc'", 60 60 "expected": IframeLoad.EXPECT_BLOCK }, -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-unsafe_eval.html
r246330 r279838 10 10 <script> 11 11 var tests = [ 12 { "name": "'unsafe-eval' is properly subsumed.", 13 "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-hashed-attributes' 'strict-dynamic' 'unsafe-eval'", 12 { "name": "'unsafe-eval' is properly subsumed.", 13 "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-hashed-attributes' 'strict-dynamic' 'unsafe-eval'", 14 14 "returned_csp_1": "style-src http://example1.com/foo/bar.html 'unsafe-eval'", 15 15 "expected": IframeLoad.EXPECT_LOAD }, 16 { "name": "No other keyword has the same effect as 'unsafe-eval'.", 17 "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-eval'", 16 { "name": "No other keyword has the same effect as 'unsafe-eval'.", 17 "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-eval'", 18 18 "returned_csp_1": "style-src http://example1.com/foo/ 'unsafe-inline'", 19 19 "expected": IframeLoad.EXPECT_BLOCK }, 20 { "name": "Other expressions have to be subsumed.", 21 "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-eval'", 20 { "name": "Other expressions have to be subsumed.", 21 "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-eval'", 22 22 "returned_csp_1": "style-src http://example1.com/foo/ 'unsafe-inline' 'unsafe-eval'", 23 23 "expected": IframeLoad.EXPECT_BLOCK }, 24 { "name": "Effective policy is properly found.", 25 "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-eval'", 24 { "name": "Effective policy is properly found.", 25 "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-eval'", 26 26 "returned_csp_1": "style-src http://example1.com/foo/ 'unsafe-hashed-attributes' 'unsafe-eval'", 27 27 "returned_csp_2": "style-src http://example1.com/foo/ 'self' 'unsafe-eval'", 28 28 "expected": IframeLoad.EXPECT_LOAD }, 29 { "name": "Required csp must allow 'unsafe-eval'.", 30 "required_csp": "style-src http://example1.com/foo/ 'self'", 29 { "name": "Required csp must allow 'unsafe-eval'.", 30 "required_csp": "style-src http://example1.com/foo/ 'self'", 31 31 "returned_csp_1": "style-src http://example1.com/foo/ 'self' 'unsafe-eval'", 32 32 "expected": IframeLoad.EXPECT_BLOCK }, 33 { "name": "Effective policy is properly found where 'unsafe-eval' is not subsumed.", 34 "required_csp": "style-src http://example1.com/foo/ 'self'", 33 { "name": "Effective policy is properly found where 'unsafe-eval' is not subsumed.", 34 "required_csp": "style-src http://example1.com/foo/ 'self'", 35 35 "returned_csp_1": "style-src 'unsafe-hashed-attributes' 'unsafe-eval'", 36 36 "returned_csp_2": "style-src 'unsafe-eval' 'unsafe-inline'", 37 37 "expected": IframeLoad.EXPECT_BLOCK }, 38 { "name": "Effective policy is properly found where 'unsafe-eval' is not part of it.", 39 "required_csp": "style-src http://example1.com/foo/ 'self'", 38 { "name": "Effective policy is properly found where 'unsafe-eval' is not part of it.", 39 "required_csp": "style-src http://example1.com/foo/ 'self'", 40 40 "returned_csp_1": "style-src 'unsafe-hashed-attributes' 'self'", 41 41 "returned_csp_2": "style-src 'unsafe-eval' 'self'", -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-unsafe_inline.html
r263605 r279838 10 10 <script> 11 11 var tests = [ 12 { "name": "'strict-dynamic' is ineffective for `style-src`.", 13 "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline' 'strict-dynamic'", 12 { "name": "'strict-dynamic' is ineffective for `style-src`.", 13 "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline' 'strict-dynamic'", 14 14 "returned_csp_1": "style-src 'unsafe-inline' http://example1.com/foo/bar.html", 15 15 "returned_csp_2": null, 16 16 "expected": IframeLoad.EXPECT_LOAD }, 17 { "name": "'unsafe-inline' is properly subsumed in `style-src`.", 18 "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline'", 17 { "name": "'unsafe-inline' is properly subsumed in `style-src`.", 18 "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline'", 19 19 "returned_csp_1": "style-src http://example1.com/foo/ 'unsafe-inline'", 20 20 "returned_csp_2": null, 21 21 "expected": IframeLoad.EXPECT_LOAD }, 22 { "name": "'unsafe-inline' is only ineffective if the effective returned csp has nonces in `style-src`.", 23 "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline'", 22 { "name": "'unsafe-inline' is only ineffective if the effective returned csp has nonces in `style-src`.", 23 "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline'", 24 24 "returned_csp_1": "style-src 'unsafe-inline' 'nonce-yay'", 25 25 "returned_csp_2": "style-src 'unsafe-inline'", 26 26 "expected": IframeLoad.EXPECT_LOAD }, 27 { "name": "'unsafe-inline' is only ineffective if the effective returned csp has hashes in `style-src`.", 28 "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline'", 27 { "name": "'unsafe-inline' is only ineffective if the effective returned csp has hashes in `style-src`.", 28 "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline'", 29 29 "returned_csp_1": "style-src 'unsafe-inline' 'sha256-abc123'", 30 30 "returned_csp_2": "style-src 'unsafe-inline'", 31 31 "expected": IframeLoad.EXPECT_LOAD }, 32 { "name": "Returned csp does not have to allow 'unsafe-inline' in `style-src` to be subsumed.", 33 "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline'", 32 { "name": "Returned csp does not have to allow 'unsafe-inline' in `style-src` to be subsumed.", 33 "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline'", 34 34 "returned_csp_1": "style-src 'self'", 35 35 "returned_csp_2": null, 36 36 "expected": IframeLoad.EXPECT_LOAD }, 37 { "name": "'unsafe-inline' does not matter if returned csp is effectively `none`.", 38 "required_csp": "style-src 'unsafe-inline'", 37 { "name": "'unsafe-inline' does not matter if returned csp is effectively `none`.", 38 "required_csp": "style-src 'unsafe-inline'", 39 39 "returned_csp_1": "style-src ", 40 40 "returned_csp_2": null, 41 41 "expected": IframeLoad.EXPECT_LOAD }, 42 { "name": "'unsafe-inline' is properly subsumed in `script-src`.", 43 "required_csp": "script-src http://example1.com/foo/ 'self' 'unsafe-inline'", 42 { "name": "'unsafe-inline' is properly subsumed in `script-src`.", 43 "required_csp": "script-src http://example1.com/foo/ 'self' 'unsafe-inline'", 44 44 "returned_csp_1": "script-src http://example1.com/foo/ 'unsafe-inline'", 45 45 "returned_csp_2": null, 46 46 "expected": IframeLoad.EXPECT_LOAD }, 47 { "name": "Returned csp only loads 'unsafe-inline' scripts with 'nonce-abc'.", 48 "required_csp": "script-src http://example1.com/foo/ 'self' 'unsafe-inline'", 47 { "name": "Returned csp only loads 'unsafe-inline' scripts with 'nonce-abc'.", 48 "required_csp": "script-src http://example1.com/foo/ 'self' 'unsafe-inline'", 49 49 "returned_csp_1": "script-src 'nonce-abc'", 50 50 "returned_csp_2": "script-src 'unsafe-inline'", 51 51 "expected": IframeLoad.EXPECT_LOAD }, 52 { "name": "'unsafe-inline' is ineffective when nonces are present.", 53 "required_csp": "script-src http://example1.com/foo/ 'self' 'unsafe-inline'", 52 { "name": "'unsafe-inline' is ineffective when nonces are present.", 53 "required_csp": "script-src http://example1.com/foo/ 'self' 'unsafe-inline'", 54 54 "returned_csp_1": "script-src 'unsafe-inline' 'nonce-abc'", 55 55 "returned_csp_2": "script-src 'unsafe-inline'", 56 56 "expected": IframeLoad.EXPECT_LOAD }, 57 { "name": "'unsafe-inline' is only ineffective if the effective returned csp has hashes in `script-src`.", 58 "required_csp": "script-src http://example1.com/foo/ 'self' 'unsafe-inline'", 57 { "name": "'unsafe-inline' is only ineffective if the effective returned csp has hashes in `script-src`.", 58 "required_csp": "script-src http://example1.com/foo/ 'self' 'unsafe-inline'", 59 59 "returned_csp_1": "script-src 'unsafe-inline' 'sha256-abc123' 'nonce-abc'", 60 60 "returned_csp_2": "script-src 'unsafe-inline'", 61 61 "expected": IframeLoad.EXPECT_LOAD }, 62 { "name": "Required csp allows `strict-dynamic`, but retuned csp does.", 63 "required_csp": "script-src http://example1.com/foo/ 'unsafe-inline' 'strict-dynamic'", 62 { "name": "Required csp allows `strict-dynamic`, but retuned csp does.", 63 "required_csp": "script-src http://example1.com/foo/ 'unsafe-inline' 'strict-dynamic'", 64 64 "returned_csp_1": "script-src 'unsafe-inline' http://example1.com/foo/bar.html", 65 65 "returned_csp_2": null, 66 66 "expected": IframeLoad.EXPECT_BLOCK }, 67 { "name": "Required csp does not allow `unsafe-inline`, but retuned csp does.", 68 "required_csp": "style-src http://example1.com/foo/ 'self'", 67 { "name": "Required csp does not allow `unsafe-inline`, but retuned csp does.", 68 "required_csp": "style-src http://example1.com/foo/ 'self'", 69 69 "returned_csp_1": "style-src 'unsafe-inline'", 70 70 "returned_csp_2": null, 71 71 "expected": IframeLoad.EXPECT_BLOCK }, 72 { "name": "Returned csp allows a nonce.", 73 "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline'", 72 { "name": "Returned csp allows a nonce.", 73 "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline'", 74 74 "returned_csp_1": "style-src 'unsafe-inline' 'nonce-abc'", 75 75 "returned_csp_2": "style-src 'nonce-abc'", 76 76 "expected": IframeLoad.EXPECT_BLOCK }, 77 { "name": "Returned csp allows a hash.", 78 "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline'", 77 { "name": "Returned csp allows a hash.", 78 "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline'", 79 79 "returned_csp_1": "style-src 'unsafe-inline' 'sha256-abc123'", 80 80 "returned_csp_2": "style-src 'sha256-abc123'", 81 81 "expected": IframeLoad.EXPECT_BLOCK }, 82 { "name": "Effective returned csp allows 'unsafe-inline'", 83 "required_csp": "style-src http://example1.com/foo/ 'self'", 82 { "name": "Effective returned csp allows 'unsafe-inline'", 83 "required_csp": "style-src http://example1.com/foo/ 'self'", 84 84 "returned_csp_1": "style-src 'unsafe-inline' https://example.test/", 85 85 "returned_csp_2": "style-src 'unsafe-inline'", 86 86 "expected": IframeLoad.EXPECT_BLOCK }, 87 { "name": "Effective returned csp does not allow 'sha512-321cba' hash.", 88 "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline' 'sha512-321cba'", 87 { "name": "Effective returned csp does not allow 'sha512-321cba' hash.", 88 "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline' 'sha512-321cba'", 89 89 "returned_csp_1": "style-src http://example1.com/foo/ 'unsafe-inline' 'nonce-yay'", 90 90 "returned_csp_2": "style-src http://example1.com/foo/ 'unsafe-inline' 'sha512-321cba'", -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/support/echo-allow-csp-from.py
r246330 r279838 1 1 import json 2 2 def main(request, response): 3 headers = [( "Content-Type","text/html")]4 if "allow_csp_from" in request.GET:5 headers.append(( "Allow-CSP-From", request.GET["allow_csp_from"]))6 message = request.GET[ "id"]7 return headers, '''3 headers = [(b"Content-Type", b"text/html")] 4 if b"allow_csp_from" in request.GET: 5 headers.append((b"Allow-CSP-From", request.GET[b"allow_csp_from"])) 6 message = request.GET[b"id"] 7 return headers, b''' 8 8 <!DOCTYPE html> 9 9 <html> … … 22 22 </head> 23 23 <body> 24 <script nonce="123"> 25 let img = document.createElement('img'); 26 img.src = "../../support/pass.png"; 27 img.onload = function() { window.top.postMessage("img loaded", '*'); } 28 document.body.appendChild(img); 29 </script> 24 30 <style> 25 31 body { … … 27 33 } 28 34 </style> 29 <script nonce="abc"> 35 <script nonce="abc"> 30 36 var response = {}; 31 37 response["id"] = "%s"; -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/support/echo-policy-multiple.py
r246330 r279838 1 1 def main(request, response): 2 headers = [( "Content-Type","text/html")]3 if "policy" in request.GET:4 headers.append(( "Content-Security-Policy", request.GET["policy"]))5 if "policy2" in request.GET:6 headers.append(( "Content-Security-Policy", request.GET["policy2"]))7 if "policy3" in request.GET:8 headers.append(( "Content-Security-Policy", request.GET["policy3"]))9 message = request.GET[ "id"]10 return headers, '''2 headers = [(b"Content-Type", b"text/html")] 3 if b"policy" in request.GET: 4 headers.append((b"Content-Security-Policy", request.GET[b"policy"])) 5 if b"policy2" in request.GET: 6 headers.append((b"Content-Security-Policy", request.GET[b"policy2"])) 7 if b"policy3" in request.GET: 8 headers.append((b"Content-Security-Policy", request.GET[b"policy3"])) 9 message = request.GET[b"id"] 10 return headers, b''' 11 11 <!DOCTYPE html> 12 12 <html> … … 15 15 </head> 16 16 <body> 17 <script nonce="abc"> 17 <script nonce="abc"> 18 18 var response = {}; 19 19 response["id"] = "%s"; -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/support/echo-required-csp.py
r254133 r279838 1 1 import json 2 3 from wptserve.utils import isomorphic_decode 4 2 5 def main(request, response): 3 6 message = {} 4 7 5 header = request.headers.get( "Test-Header-Injection");6 message[ 'test_header_injection'] = headerif header else None8 header = request.headers.get(b"Test-Header-Injection"); 9 message[u'test_header_injection'] = isomorphic_decode(header) if header else None 7 10 8 header = request.headers.get( "Sec-Required-CSP");9 message[ 'required_csp'] = headerif header else None11 header = request.headers.get(b"Sec-Required-CSP"); 12 message[u'required_csp'] = isomorphic_decode(header) if header else None 10 13 11 second_level_iframe_code = ""12 if "include_second_level_iframe" in request.GET:13 if "second_level_iframe_csp" in request.GET and request.GET["second_level_iframe_csp"] !="":14 second_level_iframe_code = '''<script>14 second_level_iframe_code = u"" 15 if b"include_second_level_iframe" in request.GET: 16 if b"second_level_iframe_csp" in request.GET and request.GET[b"second_level_iframe_csp"] != b"": 17 second_level_iframe_code = u'''<script> 15 18 var i2 = document.createElement('iframe'); 16 19 i2.src = 'echo-required-csp.py'; 17 20 i2.csp = "{0}"; 18 21 document.body.appendChild(i2); 19 </script>'''.format( request.GET["second_level_iframe_csp"])22 </script>'''.format(isomorphic_decode(request.GET[b"second_level_iframe_csp"])) 20 23 else: 21 second_level_iframe_code = '''<script>24 second_level_iframe_code = u'''<script> 22 25 var i2 = document.createElement('iframe'); 23 26 i2.src = 'echo-required-csp.py'; … … 25 28 </script>''' 26 29 27 return [( "Content-Type", "text/html"), ("Allow-CSP-From", "*")],'''30 return [(b"Content-Type", b"text/html"), (b"Allow-CSP-From", b"*")], u''' 28 31 <!DOCTYPE html> 29 32 <html> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/support/testharness-helper.sub.js
r263605 r279838 18 18 function getOrigin() { 19 19 var url = new URL("http://{{host}}:{{ports[http][0]}}/"); 20 return url. toString();20 return url.origin; 21 21 } 22 22 … … 139 139 if (e.source != i.contentWindow) 140 140 return; 141 if (!e.data.securitypolicyviolation) 142 return; 141 143 assert_equals(e.data["blockedURI"], blockedURI); 142 144 t.done(); 143 145 })); 144 146 } else { 145 // Assert iframe loads. Wait for both the load event and the postMessage. 147 // Assert iframe loads. Wait for the load event, the postMessage from the 148 // script and the img load event. 149 let postMessage_received = false; 150 let img_loaded = false; 146 151 window.addEventListener('message', t.step_func(e => { 147 152 if (e.source != i.contentWindow) 148 153 return; 149 assert_true(loaded[urlId]); 150 if (i.onloadReceived) 154 if (e.data.loaded) { 155 assert_true(loaded[urlId]); 156 postMessage_received = true; 157 } else if (e.data === "img.loaded") 158 img_loaded = true; 159 160 if (i.onloadReceived && postMessage_received && img_loaded) 151 161 t.done(); 152 162 })); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/support/w3c-import.log
r263605 r279838 18 18 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/support/echo-policy-multiple.py 19 19 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/support/echo-required-csp.py 20 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/support/embed-img-and-message-top.html 20 21 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/support/executor.html 21 22 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/support/testharness-helper.sub.js -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/w3c-import.log
r263605 r279838 15 15 ------------------------------------------------------------------------ 16 16 List of files: 17 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/META.yml 17 18 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/allow_csp_from-header.html 18 19 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/blocked-iframe-are-cross-origin.html 20 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/change-csp-attribute-and-history-navigation.html 19 21 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/idlharness.window.js 20 22 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/iframe-csp-attribute.html … … 31 33 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-none.html 32 34 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-self.html 35 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-source_list-wildcards.html 33 36 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-strict_dynamic.html 34 37 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-unsafe_eval.html -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/form-action/form-action-src-redirect-blocked.sub-expected.txt
r267651 r279838 5 5 6 6 7 FAIL Expecting logs: ["violated-directive=form-action"," TEST COMPLETE"] assert_unreached: Logging timeout, expected logs violated-directive=form-actionnot sent. Reached unreachable code7 FAIL Expecting logs: ["violated-directive=form-action","blocked-uri=http://localhost:8800/common/redirect.py?location=http://www1.localhost:8800/content-security-policy/support/postmessage-fail.html","TEST COMPLETE"] assert_unreached: Logging timeout, expected logs violated-directive=form-action,blocked-uri=http://localhost:8800/common/redirect.py?location=http://www1.localhost:8800/content-security-policy/support/postmessage-fail.html not sent. Reached unreachable code 8 8 -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/form-action/form-action-src-redirect-blocked.sub.html
r246330 r279838 8 8 <script src="/resources/testharness.js"></script> 9 9 <script src="/resources/testharnessreport.js"></script> 10 <script src='../support/logTest.sub.js?logs=["violated-directive=form-action"," TEST COMPLETE"]'></script>10 <script src='../support/logTest.sub.js?logs=["violated-directive=form-action","blocked-uri=http://{{hosts[][]}}:{{ports[http][0]}}/common/redirect.py?location=http://{{domains[www1]}}:{{ports[http][0]}}/content-security-policy/support/postmessage-fail.html","TEST COMPLETE"]'></script> 11 11 <script src="../support/alertAssert.sub.js?alerts=[]"></script> 12 12 <script> 13 13 window.addEventListener('securitypolicyviolation', function(e) { 14 14 log('violated-directive=' + e.violatedDirective); 15 log('blocked-uri=' + e.blockedURI); 15 16 }); 16 17 window.addEventListener("message", function(event) { -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-same-none-block-expected.txt
r262312 r279838 1 Blocked access to external URL http://www1.localhost:8801/content-security-policy/frame-ancestors/support/frame-ancestors.sub.html?policy= 'none'1 Blocked access to external URL http://www1.localhost:8801/content-security-policy/frame-ancestors/support/frame-ancestors.sub.html?policy=%27none%27 2 2 3 3 -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-same-self-block-expected.txt
r262312 r279838 1 Blocked access to external URL http://www1.localhost:8801/content-security-policy/frame-ancestors/support/frame-ancestors.sub.html?policy= 'self'1 Blocked access to external URL http://www1.localhost:8801/content-security-policy/frame-ancestors/support/frame-ancestors.sub.html?policy=%27self%27 2 2 3 3 -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-same-star-allow.html
r246330 r279838 2 2 <html> 3 3 <head> 4 <meta name="timeout" content="long"> 4 5 <script src="/resources/testharness.js"></script> 5 6 <script src="/resources/testharnessreport.js"></script> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/frame-ancestors-nested-same-in-same-self-allow-expected.txt
r262312 r279838 1 1 2 2 3 FAIL A 'frame-ancestors' CSP directive with a value 'same' should block render in same-origin nested frames. assert_unreached: Inner IFrame msg: The IFrame should not have been blocked. It was. Reached unreachable code 3 PASS A 'frame-ancestors' CSP directive with a value 'same' should block render in same-origin nested frames. 4 4 -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/frame-ancestors-none-block-expected.txt
r267651 r279838 1 1 2 2 3 PASS frame-ancestors-none-block 3 4 PASS A 'frame-ancestors' CSP directive with a value 'none' should block rendering. 4 5 -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/frame-ancestors-none-block.html
r246330 r279838 7 7 </head> 8 8 <body> 9 <script> 10 test = async_test("A 'frame-ancestors' CSP directive with a value 'none' should block rendering."); 9 <script> 10 async_test(t => { 11 window.addEventListener('securitypolicyviolation', t.step_func(function(e) { 12 if (e.violatedDirective === 'frame-ancestors') 13 assert_unreached('No securitypolicyviolation event shoud be raised in the parent.'); 14 })); 15 t.step_timeout(function() { t.done(); }, 2000); 16 }); 11 17 12 sameOriginFrameShouldBeBlocked("'none'"); 13 </script> 18 test = async_test("A 'frame-ancestors' CSP directive with a value 'none' should block rendering."); 19 20 sameOriginFrameShouldBeBlocked("'none'"); 21 </script> 14 22 </body> 15 23 </html> 16 -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/report-blocked-frame.sub.html
r254133 r279838 8 8 </head> 9 9 <body> 10 <iframe src="support/content-security-policy.sub.html?policy=report-uri%20 ../../support/report.py%3Fop=put%26reportID={{$id:uuid()}}%3B%20frame-ancestors%20'none'"></iframe>10 <iframe src="support/content-security-policy.sub.html?policy=report-uri%20/reporting/resources/report.py%3Fop=put%26reportID={{$id:uuid()}}%3B%20frame-ancestors%20'none'"></iframe> 11 11 <script async defer src="../support/checkReport.sub.js?reportField=violated-directive&reportValue=frame-ancestors%20'none'&reportID={{$id}}"></script> 12 12 </body> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/report-only-frame.sub.html
r254133 r279838 8 8 </head> 9 9 <body> 10 <iframe src="support/content-security-policy-report-only.sub.html?policy=report-uri%20 ../../support/report.py%3Fop=put%26reportID={{$id:uuid()}}%3B%20frame-ancestors%20'none'"></iframe>10 <iframe src="support/content-security-policy-report-only.sub.html?policy=report-uri%20/reporting/resources/report.py%3Fop=put%26reportID={{$id:uuid()}}%3B%20frame-ancestors%20'none'"></iframe> 11 11 <script async defer src="../support/checkReport.sub.js?reportField=violated-directive&reportValue=frame-ancestors%20'none'&reportID={{$id}}"></script> 12 12 </body> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/support/frame-in-frame.sub.html
r246330 r279838 5 5 <script src='/resources/testharnessreport.js'></script> 6 6 <script src='/content-security-policy/frame-ancestors/support/frame-ancestors-test.sub.js'></script> 7 8 <span id="escape">{{GET[policy]}}</span> 9 7 10 <script> 8 11 test = async_test("Testing a {{GET[child]}}-origin child with a policy of {{GET[policy]}} nested in a {{GET[parent]}}-origin parent"); 9 originFrameShouldBe("{{GET[child]}}", "{{GET[expectation]}}", "{{GET[policy]]}}"); 12 const policy = document.getElementById("escape").textContent; 13 originFrameShouldBe("{{GET[child]}}", "{{GET[expectation]}}", policy); 10 14 </script> 11 15 </body> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-about-blank-allowed-by-default.sub.html
r246330 r279838 10 10 <script src='../support/logTest.sub.js?logs=["PASS"]'></script> 11 11 <script src="../support/alertAssert.sub.js?alerts=[]"></script> 12 12 13 13 <p>These frames should not be blocked by Content-Security-Policy. 14 14 It's pointless to block about:blank iframes because … … 19 19 log("Fail"); 20 20 }); 21 </script> 22 21 </script> 22 23 23 <iframe src="about:blank"></iframe> 24 24 <object type="text/html" data="about:blank"></object> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-about-blank-allowed-by-scheme.sub.html
r246330 r279838 17 17 log("Fail"); 18 18 }); 19 </script> 20 19 </script> 20 21 21 <iframe src="about:blank"></iframe> 22 22 <div id="log"></div> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-allowed.sub.html
r246330 r279838 12 12 log("Fail"); 13 13 }); 14 14 15 15 window.addEventListener("message", function(event) { 16 16 alert_assert(event.data); … … 28 28 for (var i = 0; i < expected_alerts.length; i++) { 29 29 if (expected_alerts[i] == msg) { 30 assert_ true(expected_alerts[i] ==msg);30 assert_equals(expected_alerts[i], msg); 31 31 expected_alerts.splice(i, 1); 32 32 if (expected_alerts.length == 0) { -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-blocked.sub.html
r246330 r279838 13 13 log("violated-directive=" + e.violatedDirective); 14 14 }); 15 15 16 16 window.addEventListener("message", function(event) { 17 17 alert_assert(event.data); … … 26 26 for (var i = 0; i < expected_alerts.length; i++) { 27 27 if (expected_alerts[i] == msg) { 28 assert_ true(expected_alerts[i] ==msg);28 assert_equals(expected_alerts[i], msg); 29 29 expected_alerts.splice(i, 1); 30 30 if (expected_alerts.length == 0) { -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-cross-origin-load.sub.html
r246330 r279838 13 13 log("violated-directive=" + e.violatedDirective); 14 14 }); 15 15 16 16 window.addEventListener("message", function(event) { 17 17 alert_assert(event.data); … … 29 29 for (var i = 0; i < expected_alerts.length; i++) { 30 30 if (expected_alerts[i] == msg) { 31 assert_ true(expected_alerts[i] ==msg);31 assert_equals(expected_alerts[i], msg); 32 32 expected_alerts.splice(i, 1); 33 33 if (expected_alerts.length == 0) { … … 43 43 44 44 </script> 45 45 46 46 <p> 47 47 IFrames blocked by CSP should generate a 'load', not 'error' event, regardless of blocked state. This means they appear to be normal cross-origin loads, thereby not leaking URL information directly to JS. -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-same-document.sub.html
r263605 r279838 5 5 <script> 6 6 let crossOriginUrl = 7 "http://www1.{{host}}:{{ports[http][0]}}/content-security-policy/ support/frame.html";7 "http://www1.{{host}}:{{ports[http][0]}}/content-security-policy/frame-src/support/frame.html"; 8 8 9 async_test(async test => { 10 test.done(); 9 promise_test(async test => { 11 10 let iframe = document.createElement("iframe"); 12 11 document.body.appendChild(iframe); … … 19 18 await violation; 20 19 } 21 22 test.done();23 20 }, "Same-document navigation in an iframe blocked by CSP frame-src"); 24 21 </script> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-self-unique-origin.html
r246330 r279838 36 36 `); 37 37 if (window.async_test) { 38 async_test(t => { 38 async_test(t => { 39 39 window.addEventListener("message", e => { 40 40 if (e.data == "Test PASS") -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/w3c-import.log
r263605 r279838 23 23 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-redirect.html.headers 24 24 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-same-document-meta.sub.html 25 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-same-document.html.headers26 25 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-same-document.sub.html 26 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-same-document.sub.html.headers 27 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-sandboxed-allowed.html 28 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-sandboxed-allowed.html.headers 27 29 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-self-unique-origin.html -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/duplicate-directive.sub.html
r246330 r279838 4 4 <head> 5 5 <!-- Programmatically converted from a WebKit Reftest, please forgive resulting idiosyncracies.--> 6 <meta http-equiv="Content-Security-Policy" content="script-src 'self' 'unsafe-inline' 'unsafe-inline'; script-src 'none'; connect-src 'self';"> 6 <meta http-equiv="Content-Security-Policy" content="script-src 'self' 'unsafe-inline' 'unsafe-inline'; script-src 'none'; connect-src 'self';"> 7 7 <title>duplicate-directive</title> 8 8 <script src="/resources/testharness.js"></script> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/filesystem-urls-match-filesystem.sub.html
r246330 r279838 20 20 log("Fail"); 21 21 }); 22 22 23 23 if(!window.webkitRequestFileSystem) { 24 24 t_log.set_status(t_log.NOTRUN, "No filesystem:// support, cannot run test."); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/generic-0_1-img-src.html
r246330 r279838 16 16 var onerrorFired = false; 17 17 var t_spv = async_test("Should fire violation events for every failed violation"); 18 18 19 19 window.addEventListener("securitypolicyviolation", t_spv.step_func_done(function(e) { 20 20 assert_equals(e.violatedDirective, "img-src"); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/generic-0_10.sub.html
r254133 r279838 9 9 var t = async_test("Test that script does not fire violation event"); 10 10 window.addEventListener("securitypolicyviolation", t.unreached_func("Should not have fired a violation event")); 11 11 12 12 var head = document.getElementsByTagName('head')[0]; 13 13 var script = document.createElement('script'); … … 16 16 head.appendChild(script); 17 17 </script> 18 18 19 19 <script> 20 20 t.done(); 21 </script> 21 </script> 22 22 </head> 23 23 <body> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/generic-0_8_1.sub.html
r254133 r279838 3 3 <head> 4 4 <title>test wildcard host name matching (asterisk as part of a subdomain is not accepted)</title> 5 <meta http-equiv="Content-Security-Policy" content="script-src 'self' *w.{{host}}:{{ports[http][0]}} w*.{{host}}:{{ports[http][0]}} 'unsafe-inline';">6 <script src='/resources/testharness.js'></script>7 <script src='/resources/testharnessreport.js'></script>8 <script src='wildcardHostTestFailure.js'></script>9 5 <script> 10 6 var t_spv = async_test("Should fire violation events for every failed violation"); … … 24 20 head.appendChild(script); 25 21 </script> 22 <meta http-equiv="Content-Security-Policy" content="script-src 'self' *w.{{host}}:{{ports[http][0]}} w*.{{host}}:{{ports[http][0]}} 'unsafe-inline';"> 23 <script src='/resources/testharness.js'></script> 24 <script src='/resources/testharnessreport.js'></script> 25 <script src='wildcardHostTestFailure.js'></script> 26 26 </head> 27 27 <body> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/generic-0_9.sub.html
r254133 r279838 13 13 t.done(); 14 14 }); 15 15 16 16 var head = document.getElementsByTagName('head')[0]; 17 17 var script = document.createElement('script'); … … 23 23 <body> 24 24 <h1>test wildcard port number matching</h1> 25 <div id='log'></div> 25 <div id='log'></div> 26 26 </body> 27 27 </html> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/no-default-src.sub.html.sub.headers
r246330 r279838 4 4 Pragma: no-cache 5 5 Set-Cookie: no-default-src={{$id:uuid()}}; Path=/content-security-policy/generic/ 6 Content-Security-Policy: foobar; report-uri ../support/report.py?op=put&reportID={{$id}}6 Content-Security-Policy: foobar; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/only-valid-whitespaces-are-allowed.html
r246330 r279838 43 43 if (test.csp.indexOf("\u000A") == -1 && test.csp.indexOf("\u000D") == -1) { 44 44 async_test(t => { 45 var url = "support/load_img_and_post_result_ meta.sub.html?csp=" + encodeURIComponent(test.csp);45 var url = "support/load_img_and_post_result_header.html?csp=" + encodeURIComponent(test.csp); 46 46 test_image_loads_as_expected(test, t, url); 47 47 }, test.name + " - HTTP header"); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/policy-inherited-correctly-by-plznavigate.html.sub.headers
r246330 r279838 3 3 Pragma: no-cache 4 4 Set-Cookie: policy-inherited-correctly-by-plznavigate={{$id:uuid()}}; Path=/content-security-policy/generic/ 5 Content-Security-Policy: frame-src 'none'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}}5 Content-Security-Policy: frame-src 'none'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/support/304-response.py
r246330 r279838 1 1 def main(request, response): 2 if request.headers.get( "If-None-Match"):2 if request.headers.get(b"If-None-Match"): 3 3 # we are now receing the second request, we will send back a different CSP 4 4 # with the 304 response 5 5 response.status = 304 6 headers = [( "Content-Type","text/html"),7 ( "Content-Security-Policy","script-src 'nonce-def' 'sha256-IIB78ZS1RMMrAWpsLg/RrDbVPhI14rKm3sFOeKPYulw=';"),8 ( "Cache-Control","private, max-age=0, must-revalidate"),9 ( "ETag","123456")]10 return headers, ""6 headers = [(b"Content-Type", b"text/html"), 7 (b"Content-Security-Policy", b"script-src 'nonce-def' 'sha256-IIB78ZS1RMMrAWpsLg/RrDbVPhI14rKm3sFOeKPYulw=';"), 8 (b"Cache-Control", b"private, max-age=0, must-revalidate"), 9 (b"ETag", b"123456")] 10 return headers, u"" 11 11 else: 12 headers = [( "Content-Type","text/html"),13 ( "Content-Security-Policy","script-src 'nonce-abc' 'sha256-IIB78ZS1RMMrAWpsLg/RrDbVPhI14rKm3sFOeKPYulw=';"),14 ( "Cache-Control","private, max-age=0, must-revalidate"),15 ( "Etag","123456")]16 return headers, '''12 headers = [(b"Content-Type", b"text/html"), 13 (b"Content-Security-Policy", b"script-src 'nonce-abc' 'sha256-IIB78ZS1RMMrAWpsLg/RrDbVPhI14rKm3sFOeKPYulw=';"), 14 (b"Cache-Control", b"private, max-age=0, must-revalidate"), 15 (b"Etag", b"123456")] 16 return headers, u''' 17 17 <!DOCTYPE html> 18 18 <html> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/w3c-import.log
r254133 r279838 35 35 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/generic-0_8_1.sub.html 36 36 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/generic-0_9.sub.html 37 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/invalid-characters-in-policy.html 37 38 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/negativeTests.js 38 39 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/no-default-src.sub.html … … 44 45 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/policy-inherited-correctly-by-plznavigate.html.sub.headers 45 46 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/positiveTest.js 47 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/test-case.sub.js 46 48 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/unreached.js 47 49 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/wildcardHostTest.js -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/img-src/icon-allowed.sub.html
r246330 r279838 11 11 var t = async_test("Test that image loads"); 12 12 window.addEventListener("securitypolicyviolation", t.unreached_func("Should not have triggered any violation events")); 13 13 14 14 function createLink(rel, src) { 15 15 var link = document.createElement('link'); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/img-src/icon-blocked.sub.html
r246330 r279838 15 15 assert_true(e.blockedURI.endsWith('/support/fail.png')); 16 16 })); 17 17 18 18 function createLink(rel, src) { 19 19 var link = document.createElement('link'); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/img-src/img-src-self-unique-origin.html
r246330 r279838 36 36 `); 37 37 if (window.async_test) { 38 async_test(t => { 38 async_test(t => { 39 39 window.addEventListener("message", e => { 40 40 if (e.data == "Test PASS") -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/img-src/report-blocked-data-uri.sub.html
r246330 r279838 18 18 }); 19 19 </script> 20 20 21 21 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw=="> 22 22 <div id="log"></div> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/document-write-iframe.html
r246330 r279838 4 4 <script src="/resources/testharness.js"></script> 5 5 <script src="/resources/testharnessreport.js"></script> 6 6 <title>document.open() does not change Content Security Policies</title> 7 7 </head> 8 8 <body> 9 9 <script> 10 var t0 = async_test("Image loaded in srcdoc iframe using document.write is blocked"); 11 var t1 = async_test("Image loaded in normal iframe using document.write is blocked"); 12 var t2 = async_test("Image loaded directly in simple srcdoc iframe is blocked"); 10 let message_from = (w) => { 11 return new Promise(resolve => { 12 let listener = msg => { 13 if (msg.source != w) 14 return; 15 window.removeEventListener('message', listener); 16 resolve(msg.data); 17 }; 18 window.addEventListener('message', listener); 19 }); 20 }; 13 21 14 window.onmessage = function(e) {15 var current_test;16 if (e.data.type == "spv0") {17 current_test = t0;18 } else if (e.data.type == "spv1") {19 current_test = t1;20 } else if (e.data.type == "spv2") {21 current_test = t2;22 } else {23 t0.step(function() {assert_true(false, "Unexpected message received from child frames")});24 t1.step(function() {assert_true(false, "Unexpected message received from child frames")});25 t2.step(function() {assert_true(false, "Unexpected message received from child frames")});26 }22 var documentBody = function(should_load) { 23 let image = should_load ? "pass.png" : "fail.png"; 24 return ` 25 <script> 26 function loaded() { 27 window.top.postMessage("loaded", '*'); 28 }; 29 window.addEventListener('securitypolicyviolation', function(e) { 30 window.top.postMessage("blocked", '*'); 31 }); 32 </scr`+`ipt> 33 <img src='/content-security-policy/support/${image}' onload='loaded()'>`; 34 }; 27 35 28 current_test.step(function() { 29 assert_equals(e.data.violatedDirective, 'img-src'); 30 current_test.done(); 31 }); 32 } 33 </script> 36 promise_test(async () => { 37 let iframe = document.createElement('iframe'); 38 document.body.appendChild(iframe); 34 39 35 <!--As discovered thanks to crbug.com/920531, there is a bug in CSP where the 36 CSP is not inherited when using document.open/document.write to edit a 37 document's contents. --> 38 <iframe id="frame1" srcdoc=""></iframe> 40 let msg = message_from(iframe.contentWindow); 41 let doc = iframe.contentWindow.document; 42 doc.open(); 43 doc.write("<html><body>" + documentBody(false) + "</body></html>"); 44 doc.close(); 45 assert_equals(await msg, "blocked"); 46 }, "document.open() keeps inherited CSPs on empty iframe."); 39 47 40 <!-- This is speculatively correct https://github.com/whatwg/html/issues/4510 --> 41 <iframe id="frame2" src="/content-security-policy/common/blank.html"></iframe> 48 promise_test(async () => { 49 let iframe = document.createElement('iframe'); 50 let loaded = new Promise(resolve => iframe.onload = resolve); 51 iframe.src = "/common/blank.html"; 52 document.body.appendChild(iframe); 53 await loaded; 42 54 43 <!--<script> 44 window.addEventListener('securitypolicyviolation', function(e) { 45 window.top.postMessage({type: 'spv2', violatedDirective: e.violatedDirective}, '*'); 46 }); 47 </script> 48 <img src='/content-security-policy/support/fail.png'> 49 --> 50 <iframe srcdoc="<script>window.addEventListener('securitypolicyviolation', function(e) {window.top.postMessage({type: 'spv2', violatedDirective: e.violatedDirective}, '*');});</script><img src='/content-security-policy/support/fail.png'>"></iframe> 51 <script> 52 var frames = ['frame1', 'frame2']; 53 for (var i = 0; i < frames.length; i++) { 54 var body_text = ['<script>', 55 ' window.addEventListener("securitypolicyviolation", function(e) {', 56 ' window.top.postMessage({type: "spv'+ i + '", violatedDirective: e.violatedDirective}, "*");', 57 ' });', 58 '</scr' + 'ipt>', 59 '<img src="/content-security-policy/support/fail.png">'].join('\n'); 55 let msg = message_from(iframe.contentWindow); 56 let doc = iframe.contentWindow.document; 57 doc.open(); 58 doc.write("<html><body>" + documentBody(true) + "</body></html>"); 59 doc.close(); 60 assert_equals(await msg, "loaded"); 61 }, "document.open() does not change delivered CSPs."); 60 62 61 var e = document.getElementById(frames[i]);62 var n = e.contentWindow.document;63 n.open();64 n.write("<html><body>" + body_text + "</body></html>");65 n.close();66 }67 63 </script> 68 64 </body> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/iframe-all-local-schemes.sub-expected.txt
r267651 r279838 1 1 2 2 PASS <iframe>'s about:blank inherits policy. 3 PASS window about:blank inherits policy. 3 4 PASS <iframe srcdoc>'s inherits policy. 4 5 PASS <iframe src='blob:...'>'s inherits policy. 6 PASS window url='blob:...' inherits policy. 5 7 PASS <iframe src='data:...'>'s inherits policy. 6 8 PASS <iframe src='javascript:...'>'s inherits policy (static <img> is blocked) 9 PASS window url='javascript:...'>'s inherits policy (static <img> is blocked) 7 10 PASS <iframe src='javascript:...'>'s inherits policy (dynamically inserted <img> is blocked) 8 11 PASS <iframe sandbox src='blob:...'>'s inherits policy. (opaque origin sandbox) -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/iframe-all-local-schemes.sub.html
r263605 r279838 18 18 } 19 19 20 function wait_for_error_from_window(opened_window, test) { 21 window.addEventListener('message', test.step_func(e => { 22 if (e.source != opened_window) 23 return; 24 assert_equals(e.data, "error"); 25 opened_window.close(); 26 test.done(); 27 })); 28 } 29 20 30 async_test(t => { 21 31 var i = document.createElement('iframe'); … … 28 38 img.src = "{{location[server]}}/images/red-16x16.png"; 29 39 }, "<iframe>'s about:blank inherits policy."); 40 41 async_test(t => { 42 var w = window.open("about:blank"); 43 44 let then = t.step_func(() => { 45 then = () => {}; 46 var img = w.document.createElement('img'); 47 img.onerror = t.step_func_done(_ => w.close()); 48 img.onload = t.unreached_func(); 49 w.document.body.appendChild(img); 50 img.src = "{{location[server]}}/images/red-16x16.png"; 51 }); 52 53 // There are now interoperable way to wait for the initial about:blank 54 // document to load. Chrome loads it synchronously, hence we can't wait for 55 // w.onload. On the other side Firefox loads the initial empty document 56 // later and we can wait for the onload event. 57 w.onload = then; 58 setTimeout(then, 200); 59 60 // Navigations to about:blank happens synchronously. There is no need to 61 // wait for the document to load. 62 }, "window about:blank inherits policy."); 30 63 31 64 async_test(t => { … … 60 93 61 94 async_test(t => { 95 var b = new Blob( 96 [` 97 <img src='{{location[server]}}/images/red-16x16.png' 98 onload='window.opener.postMessage("load", "*");' 99 onerror='window.opener.postMessage("error", "*");' 100 > 101 `], {type:"text/html"}); 102 let url = URL.createObjectURL(b); 103 var w = window.open(url); 104 wait_for_error_from_window(w, t); 105 }, "window url='blob:...' inherits policy."); 106 107 async_test(t => { 62 108 var i = document.createElement('iframe'); 63 109 i.src = `data:text/html,<img src='{{location[server]}}/images/red-16x16.png' … … 70 116 document.body.appendChild(i); 71 117 }, "<iframe src='data:...'>'s inherits policy."); 118 119 // Opening a window toward a data-url isn't allowed anymore. Hence, it can't 120 // be tested. 72 121 73 122 async_test(t => { … … 82 131 document.body.appendChild(i); 83 132 }, "<iframe src='javascript:...'>'s inherits policy (static <img> is blocked)"); 133 134 async_test(t => { 135 let url = `javascript:"<img src='{{location[server]}}/images/red-16x16.png' 136 onload='window.opener.postMessage(\\"load\\", \\"*\\");' 137 onerror='window.opener.postMessage(\\"error\\", \\"*\\");' 138 >"`; 139 140 let w = window.open(url); 141 wait_for_error_from_window(w, t); 142 }, "window url='javascript:...'>'s inherits policy (static <img> is blocked)"); 84 143 85 144 // Same as the previous javascript-URL test, but instead of loading the <img> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/sandboxed-blob-scheme.html.sub.headers
r246330 r279838 3 3 Pragma: no-cache 4 4 Set-Cookie: sandboxed-blob-scheme={{$id:uuid()}}; Path=/content-security-policy/inheritance/ 5 Content-Security-Policy: script-src 'nonce-abc'; report-uri http://{{host}}:{{ports[http][0]}}/ content-security-policy/support/report.py?op=put&reportID={{$id}}5 Content-Security-Policy: script-src 'nonce-abc'; report-uri http://{{host}}:{{ports[http][0]}}/reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/sandboxed-data-scheme.html.sub.headers
r246330 r279838 3 3 Pragma: no-cache 4 4 Set-Cookie: sandboxed-data-scheme={{$id:uuid()}}; Path=/content-security-policy/inheritance/ 5 Content-Security-Policy: script-src 'nonce-abc'; report-uri http://{{host}}:{{ports[http][0]}}/ content-security-policy/support/report.py?op=put&reportID={{$id}}5 Content-Security-Policy: script-src 'nonce-abc'; report-uri http://{{host}}:{{ports[http][0]}}/reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/support/navigate-self-to-blob.html.sub.headers
r246330 r279838 2 2 Cache-Control: no-store, no-cache, must-revalidate 3 3 Pragma: no-cache 4 Content-Security-Policy: {{GET[csp]}}; report-uri http://{{host}}:{{ports[http][0]}}/ content-security-policy/support/report.py?op=put&reportID={{GET[report_id]}}4 Content-Security-Policy: {{GET[csp]}}; report-uri http://{{host}}:{{ports[http][0]}}/reporting/resources/report.py?op=put&reportID={{GET[report_id]}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/support/w3c-import.log
r263605 r279838 16 16 List of files: 17 17 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/support/empty.html 18 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/support/iframe-do.sub.html 19 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/support/javascript-url-srcdoc-cross-origin-iframe-inheritance-helper.sub.html 20 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/support/message-opener-and-navigate-back.html 21 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/support/message-top-and-navigate-back.html 22 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/support/navigate-parent-to-blob.html 18 23 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/support/navigate-self-to-blob.html 19 24 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/support/navigate-self-to-blob.html.sub.headers 25 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/support/navigate-self-to-javascript.html 26 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/support/postmessage-opener.html 27 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/support/postmessage-top.html 20 28 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/support/srcdoc-child-frame.html -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/unsandboxed-blob-scheme.html.sub.headers
r246330 r279838 3 3 Pragma: no-cache 4 4 Set-Cookie: unsandboxed-blob-scheme={{$id:uuid()}}; Path=/content-security-policy/inheritance/ 5 Content-Security-Policy: script-src 'nonce-abc'; report-uri http://{{host}}:{{ports[http][0]}}/ content-security-policy/support/report.py?op=put&reportID={{$id}}5 Content-Security-Policy: script-src 'nonce-abc'; report-uri http://{{host}}:{{ports[http][0]}}/reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/unsandboxed-data-scheme.html.sub.headers
r246330 r279838 3 3 Pragma: no-cache 4 4 Set-Cookie: unsandboxed-data-scheme={{$id:uuid()}}; Path=/content-security-policy/inheritance/ 5 Content-Security-Policy: script-src 'nonce-abc'; report-uri http://{{host}}:{{ports[http][0]}}/ content-security-policy/support/report.py?op=put&reportID={{$id}}5 Content-Security-Policy: script-src 'nonce-abc'; report-uri http://{{host}}:{{ports[http][0]}}/reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/w3c-import.log
r263605 r279838 17 17 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/blob-url-in-child-frame-self-navigate-inherits.sub.html 18 18 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/blob-url-in-main-window-self-navigate-inherits.sub.html 19 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/blob-url-inherits-from-initiator.sub.html 19 20 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/document-write-iframe.html 20 21 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/frame-src-javascript-url.html 22 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/history-iframe.sub.html 23 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/history.sub.html 21 24 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/iframe-all-local-schemes-inherit-self.sub.html 22 25 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/iframe-all-local-schemes.sub.html 23 26 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/iframe-srcdoc-inheritance.html 27 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/inheritance-from-initiator.sub.html 24 28 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/inherited-csp-list-modifications-are-local.html 29 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/javascript-url-open-in-main-window.html 30 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/javascript-url-srcdoc-cross-origin-iframe-inheritance.html 31 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/location-reload.html 25 32 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/sandboxed-blob-scheme.html 26 33 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/sandboxed-blob-scheme.html.sub.headers … … 31 38 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/unsandboxed-data-scheme.html 32 39 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/unsandboxed-data-scheme.html.sub.headers 40 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/window-open-local-after-network-scheme.sub.html 33 41 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/window.html -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/support/connect-src-allow.sub.js
r254133 r279838 2 2 importScripts("{{location[server]}}/content-security-policy/support/testharness-helper.js"); 3 3 4 let base_same_origin_url = 5 "{{location[server]}}/content-security-policy/support/resource.py"; 6 let base_cross_origin_url = 7 "https://{{hosts[][www]}}:{{ports[https][1]}}" + 8 "/content-security-policy/support/resource.py"; 9 4 10 // Same-origin 5 async_test(t => {6 var url = "{{location[server]}}/content-security-policy/support/resource.py?same-origin-fetch";11 promise_test(t => { 12 let url = `${base_same_origin_url}?same-origin-fetch`; 7 13 assert_no_csp_event_for_url(t, url); 8 14 9 fetch(url)10 .then(t.step_func _done(r => assert_equals(r.status, 200)));11 }, "Same-origin 'fetch()' in " + self.location.protocol + self.location.search);15 return fetch(url) 16 .then(t.step_func(r => assert_equals(r.status, 200))); 17 }, "Same-origin 'fetch()' in " + self.location.protocol + " without CSP"); 12 18 13 async_test(t => { 14 var url = "{{location[server]}}/content-security-policy/support/resource.py?same-origin-xhr"; 19 // XHR is not available in service workers. 20 if (self.XMLHttpRequest) { 21 promise_test(t => { 22 let url = `${base_same_origin_url}?same-origin-xhr`; 23 assert_no_csp_event_for_url(t, url); 24 25 return new Promise((resolve, reject) => { 26 let xhr = new XMLHttpRequest(); 27 xhr.open("GET", url); 28 xhr.onload = resolve; 29 xhr.onerror = _ => reject("xhr.open should success."); 30 xhr.send(); 31 }); 32 }, "Same-origin XHR in " + self.location.protocol + " without CSP"); 33 } 34 35 // Cross-origin 36 promise_test(t => { 37 let url = `${base_cross_origin_url}?cross-origin-fetch`; 15 38 assert_no_csp_event_for_url(t, url); 16 39 17 var xhr = new XMLHttpRequest(); 18 xhr.open("GET", url); 19 xhr.onload = t.step_func_done(); 20 xhr.onerror = t.unreached_func(); 21 xhr.send(); 22 }, "Same-origin XHR in " + self.location.protocol + self.location.search); 40 return fetch(url) 41 .then(t.step_func(r => assert_equals(r.status, 200))); 42 }, "Cross-origin 'fetch()' in " + self.location.protocol + " without CSP"); 23 43 24 // Cross-origin 25 async_test(t => { 26 var url = "http://{{hosts[alt][]}}:{{ports[http][1]}}/content-security-policy/support/resource.py?cross-origin-fetch"; 44 // XHR is not available in service workers. 45 if (self.XMLHttpRequest) { 46 promise_test(t => { 47 let url = `${base_cross_origin_url}?cross-origin-xhr`; 48 assert_no_csp_event_for_url(t, url); 49 50 return new Promise((resolve, reject) => { 51 let xhr = new XMLHttpRequest(); 52 xhr.open("GET", url); 53 xhr.onload = resolve; 54 xhr.onerror = _ => reject("xhr.open should success."); 55 xhr.send(); 56 }); 57 }, "Cross-origin XHR in " + self.location.protocol + " without CSP"); 58 } 59 60 // Same-origin redirecting to cross-origin 61 promise_test(t => { 62 let url = `{{location[server]}}/common/redirect-opt-in.py?` + 63 `status=307&location=${base_cross_origin_url}?cross-origin-fetch`; 27 64 assert_no_csp_event_for_url(t, url); 28 65 29 fetch(url) 30 .then(t.step_func_done(r => assert_equals(r.status, 200))); 31 }, "Cross-origin 'fetch()' in " + self.location.protocol + self.location.search); 32 33 async_test(t => { 34 var url = "http://{{hosts[alt][]}}:{{ports[http][1]}}/content-security-policy/support/resource.py?cross-origin-xhr"; 35 assert_no_csp_event_for_url(t, url); 36 37 var xhr = new XMLHttpRequest(); 38 xhr.open("GET", url); 39 xhr.onload = t.step_func_done(); 40 xhr.onerror = t.unreached_func(); 41 xhr.send(); 42 }, "Cross-origin XHR in " + self.location.protocol + self.location.search); 43 44 // Same-origin redirecting to cross-origin 45 async_test(t => { 46 var url = "{{location[server]}}/common/redirect-opt-in.py?status=307&location=http://{{hosts[alt][]}}:{{ports[http][1]}}/content-security-policy/support/resource.py?cross-origin-fetch"; 47 assert_no_csp_event_for_url(t, url); 48 49 fetch(url) 50 .then(t.step_func_done(r => assert_equals(r.status, 200))); 51 }, "Same-origin => cross-origin 'fetch()' in " + self.location.protocol + self.location.search); 66 return fetch(url) 67 .then(t.step_func(r => assert_equals(r.status, 200))); 68 }, "Same-origin => cross-origin 'fetch()' in " + self.location.protocol + 69 " without CSP"); 52 70 53 71 done(); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/support/connect-src-self.sub.js
r263605 r279838 2 2 importScripts("{{location[server]}}/content-security-policy/support/testharness-helper.js"); 3 3 4 let base_same_origin_url = 5 "{{location[server]}}/content-security-policy/support/resource.py"; 6 let base_cross_origin_url = 7 "https://{{hosts[][www]}}:{{ports[https][1]}}" + 8 "/content-security-policy/support/resource.py"; 9 4 10 // Same-origin 5 11 promise_test(t => { 6 var url = "{{location[server]}}/common/text-plain.txt?same-origin-fetch";12 let url = `${base_same_origin_url}?same-origin-fetch`; 7 13 assert_no_csp_event_for_url(t, url); 8 14 9 15 return fetch(url) 10 16 .then(t.step_func(r => assert_equals(r.status, 200))); 11 }, "Same-origin 'fetch()' in " + self.location.protocol + self.location.search); 17 }, "Same-origin 'fetch()' in " + self.location.protocol + 18 " with {{GET[test-name]}}"); 12 19 13 promise_test(t => { 14 var url = "{{location[server]}}/common/text-plain.txt?same-origin-xhr"; 15 assert_no_csp_event_for_url(t, url); 20 // XHR is not available in service workers. 21 if (self.XMLHttpRequest) { 22 promise_test(t => { 23 let url = `${base_same_origin_url}?same-origin-xhr`; 24 assert_no_csp_event_for_url(t, url); 16 25 17 return new Promise((resolve, reject) => { 18 var xhr = new XMLHttpRequest(); 19 xhr.open("GET", url); 20 xhr.onload = t.step_func(resolve); 21 xhr.onerror = t.step_func(_ => reject("xhr.open should success.")); 22 xhr.send(); 23 }); 24 }, "Same-origin XHR in " + self.location.protocol + self.location.search); 26 return new Promise((resolve, reject) => { 27 let xhr = new XMLHttpRequest(); 28 xhr.open("GET", url); 29 xhr.onload = resolve; 30 xhr.onerror = _ => reject("xhr.open should success."); 31 xhr.send(); 32 }); 33 }, "Same-origin XHR in " + self.location.protocol + 34 " with {{GET[test-name]}}"); 35 } 36 37 let fetch_cross_origin_url = `${base_cross_origin_url}?cross-origin-fetch`; 25 38 26 39 // Cross-origin 27 40 promise_test(t => { 28 var url = "http://{{hosts[alt][]}}:{{ports[http][1]}}/common/text-plain.txt?cross-origin-fetch";41 let url = fetch_cross_origin_url; 29 42 30 43 return Promise.all([ 31 // TODO(mkwst): A 'securitypolicyviolation' event should fire.44 waitUntilCSPEventForURL(t, url), 32 45 fetch(url) 33 .catch(t.step_func(e => assert_true(e instanceof TypeError))) 46 .then(t.step_func(_ => assert_unreached( 47 "cross-origin fetch should have thrown."))) 48 .catch(t.step_func(e => assert_true(e instanceof TypeError))) 34 49 ]); 35 }, "Cross-origin 'fetch()' in " + self.location.protocol + self.location.search); 50 }, "Cross-origin 'fetch()' in " + self.location.protocol + 51 " with {{GET[test-name]}}"); 36 52 37 promise_test(t => { 38 var url = "http://{{hosts[alt][]}}:{{ports[http][1]}}/common/text-plain.txt?cross-origin-xhr"; 53 let xhr_cross_origin_url = `${base_cross_origin_url}?cross-origin-xhr`; 39 54 40 return Promise.all([ 41 // TODO(mkwst): A 'securitypolicyviolation' event should fire. 42 new Promise((resolve, reject) => { 43 var xhr = new XMLHttpRequest(); 44 xhr.open("GET", url); 45 xhr.onload = t.step_func(_ => reject("xhr.open should have thrown.")); 46 xhr.onerror = t.step_func(resolve); 47 xhr.send(); 48 }) 49 ]); 50 }, "Cross-origin XHR in " + self.location.protocol + self.location.search); 55 // XHR is not available in service workers. 56 if (self.XMLHttpRequest) { 57 promise_test(t => { 58 let url = xhr_cross_origin_url; 59 60 return Promise.all([ 61 waitUntilCSPEventForURL(t, url), 62 new Promise((resolve, reject) => { 63 let xhr = new XMLHttpRequest(); 64 xhr.open("GET", url); 65 xhr.onload = _ => reject("xhr.open should have thrown."); 66 xhr.onerror = resolve; 67 xhr.send(); 68 }) 69 ]); 70 }, "Cross-origin XHR in " + self.location.protocol + 71 " with {{GET[test-name]}}"); 72 } 73 74 let redirect_url = `{{location[server]}}/common/redirect-opt-in.py?` + 75 `status=307&location=${fetch_cross_origin_url}`; 51 76 52 77 // Same-origin redirecting to cross-origin 53 78 promise_test(t => { 54 var url = "{{location[server]}}/common/redirect-opt-in.py?status=307&location=http://{{hosts[alt][]}}:{{ports[http][1]}}/common/text-plain.txt?cross-origin-fetch";79 let url = redirect_url; 55 80 56 // TODO(mkwst): A 'securitypolicyviolation' event should fire. 57 return promise_rejects_js(t, TypeError, fetch(url)); 58 }, "Same-origin => cross-origin 'fetch()' in " + self.location.protocol + self.location.search); 81 return Promise.all([ 82 waitUntilCSPEventForURL(t, url), 83 fetch(url) 84 .then(t.step_func(_ => assert_unreached( 85 "cross-origin redirect should have thrown."))) 86 .catch(t.step_func(e => assert_true(e instanceof TypeError))) 87 ]); 88 }, "Same-origin => cross-origin 'fetch()' in " + self.location.protocol + 89 " with {{GET[test-name]}}"); 90 91 let expected_blocked_urls = self.XMLHttpRequest 92 ? [ fetch_cross_origin_url, xhr_cross_origin_url, redirect_url ] 93 : [ fetch_cross_origin_url, redirect_url ]; 94 95 promise_test(async t => { 96 let report_url = `{{location[server]}}/reporting/resources/report.py` + 97 `?op=retrieve_report&reportID={{GET[id]}}` + 98 `&min_count=${expected_blocked_urls.length}`; 99 100 let response = await fetch(report_url); 101 assert_equals(response.status, 200, "Fetching reports failed"); 102 103 let response_json = await response.json(); 104 let reports = response_json.map(x => x["csp-report"]); 105 106 assert_array_equals( 107 reports.map(x => x["blocked-uri"]).sort(), 108 expected_blocked_urls.sort(), 109 "Reports do not match"); 110 reports.forEach(x => { 111 assert_equals( 112 x["violated-directive"], "connect-src", 113 "Violated directive in report does not match"); 114 assert_equals( 115 x["effective-directive"], "connect-src", 116 "Effective directive in report does not match"); 117 assert_equals( 118 x["disposition"], "enforce", 119 "Effective directive in report does not match"); 120 }); 121 }, "Reports match in " + self.location.protocol + " with {{GET[test-name]}}"); 59 122 60 123 done(); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/support/script-src-allow.sub.js
r254133 r279838 2 2 3 3 test(t => { 4 importScripts("http://{{hosts[alt][]}}:{{ports[http][1]}}/content-security-policy/support/testharness-helper.js"); 5 }, "Cross-origin `importScripts()` not blocked in " + self.location.protocol + self.location.search); 4 importScripts("https://{{hosts[][www]}}:{{ports[https][1]}}" + 5 "/content-security-policy/support/testharness-helper.js"); 6 }, "Cross-origin `importScripts()` not blocked in " + self.location.protocol + 7 " withour CSP"); 6 8 7 9 test(t => { 8 10 assert_equals(2, eval("1+1")); 9 11 assert_equals(2, (new Function("return 1+1;"))()); 10 }, "`eval()` not blocked in " + self.location.protocol + self.location.search); 12 }, "`eval()` not blocked in " + self.location.protocol + 13 " without CSP"); 11 14 12 15 async_test(t => { … … 14 17 15 18 setTimeout("self.callback();", 1); 16 }, "`setTimeout([string])` not blocked in " + self.location.protocol + self.location.search); 19 setTimeout(t.step_func(_ => 20 assert_unreached("callback not called.")), 2); 21 }, "`setTimeout([string])` not blocked in " + self.location.protocol + 22 " without CSP"); 17 23 18 24 done(); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/support/script-src-self.sub.js
r263605 r279838 2 2 importScripts("{{location[server]}}/content-security-policy/support/testharness-helper.js"); 3 3 4 test(t => { 4 let importscripts_url ="https://{{hosts[][www]}}:{{ports[https][1]}}" + 5 "/content-security-policy/support/var-a.js"; 6 7 promise_test(async t => { 5 8 self.a = false; 6 9 assert_throws_dom("NetworkError", 7 _ => importScripts( "http://{{hosts[alt][]}}:{{ports[http][1]}}/content-security-policy/support/var-a.js"),10 _ => importScripts(importscripts_url), 8 11 "importScripts should throw `NetworkError`"); 9 12 assert_false(self.a); 10 }, "Cross-origin `importScripts()` blocked in " + self.location.protocol + self.location.search); 13 return waitUntilCSPEventForURL(t, importscripts_url); 14 }, "Cross-origin `importScripts()` blocked in " + self.location.protocol + 15 " with {{GET[test-name]}}"); 11 16 12 test(t => {17 promise_test(t => { 13 18 assert_throws_js(EvalError, 14 19 _ => eval("1 + 1"), … … 18 23 _ => new Function("1 + 1"), 19 24 "`new Function()` should throw 'EvalError'."); 20 }, "`eval()` blocked in " + self.location.protocol + self.location.search); 25 return Promise.all([ 26 waitUntilCSPEventForEval(t, 19), 27 waitUntilCSPEventForEval(t, 23), 28 ]); 29 }, "`eval()` blocked in " + self.location.protocol + 30 " with {{GET[test-name]}}"); 21 31 22 async_test(t => { 23 waitUntilCSPEventForEval(t, 27) 24 .then(t.step_func_done()); 32 promise_test(t => { 33 self.setTimeoutTest = t; 34 let result = setTimeout("(self.setTimeoutTest.unreached_func(" + 35 "'setTimeout([string]) should not execute.'))()", 1); 36 assert_equals(result, 0); 37 return waitUntilCSPEventForEval(t, 34); 38 }, "`setTimeout([string])` blocked in " + self.location.protocol + 39 " with {{GET[test-name]}}"); 25 40 26 self.setTimeoutTest = t; 27 var result = setTimeout("(self.setTimeoutTest.unreached_func('setTimeout([string]) should not execute.'))()", 1); 28 assert_equals(result, 0); 29 }, "`setTimeout([string])` blocked in " + self.location.protocol + self.location.search); 41 promise_test(async t => { 42 let report_url = "{{location[server]}}/reporting/resources/report.py" + 43 "?op=retrieve_report&reportID={{GET[id]}}&min_count=4"; 44 45 let response = await fetch(report_url); 46 assert_equals(response.status, 200, "Fetching reports failed"); 47 48 let response_json = await response.json(); 49 let reports = response_json.map(x => x["csp-report"]); 50 51 assert_array_equals( 52 reports.map(x => x["blocked-uri"]).sort(), 53 [ importscripts_url, "eval", "eval", "eval" ].sort(), 54 "Reports do not match"); 55 assert_array_equals( 56 reports.map(x => x["violated-directive"]).sort(), 57 [ "script-src-elem", "script-src", "script-src", "script-src" ].sort(), 58 "Violated directive in report does not match"); 59 assert_array_equals( 60 reports.map(x => x["effective-directive"]).sort(), 61 [ "script-src-elem", "script-src", "script-src", "script-src" ].sort(), 62 "Effective directive in report does not match"); 63 reports.forEach(x => { 64 assert_equals( 65 x["disposition"], "enforce", 66 "Disposition in report does not match"); 67 }); 68 }, "Reports are sent for " + self.location.protocol + 69 " with {{GET[test-name]}}"); 30 70 31 71 done(); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/support/w3c-import.log
r246330 r279838 16 16 List of files: 17 17 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/support/connect-src-allow.sub.js 18 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/support/connect-src-self-report-only.sub.js 19 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/support/connect-src-self-report-only.sub.js.sub.headers 18 20 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/support/connect-src-self.sub.js 19 21 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/support/script-src-allow.sub.js -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/w3c-import.log
r246330 r279838 15 15 ------------------------------------------------------------------------ 16 16 List of files: 17 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicated-inheritance.html 18 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicated-script.html 19 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/shared-inheritance.html 20 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/shared-script.html 17 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicatedworker-connect-src.html 18 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicatedworker-connect-src.html.sub.headers 19 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicatedworker-report-only.html 20 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicatedworker-report-only.html.sub.headers 21 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicatedworker-script-src.html 22 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicatedworker-script-src.html.sub.headers 23 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/serviceworker-connect-src.https.sub.html 24 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/serviceworker-report-only.https.sub.html 25 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/serviceworker-script-src.https.sub.html 26 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/sharedworker-connect-src.sub.html 27 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/sharedworker-report-only.sub.html 28 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/sharedworker-script-src.sub.html -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/media-src/media-src-7_1_2.sub.html
r246330 r279838 20 20 assert_equals(e.blockedURI, mediaURL); 21 21 if (--test_count <= 0) { 22 t_spv.done(); 22 t_spv.done(); 23 23 } 24 24 })); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/media-src/media-src-7_2_2.sub.html
r246330 r279838 20 20 assert_equals(e.blockedURI, mediaURL); 21 21 if (--test_count <= 0) { 22 t_spv.done(); 22 t_spv.done(); 23 23 } 24 24 })); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/media-src/media-src-7_3.sub.html
r254133 r279838 3 3 <head> 4 4 <title>Video track src attribute must match src list - positive test</title> 5 <meta http-equiv="Content-Security-Policy" content="script-src * 'unsafe-inline'; media-src 'self' {{hosts[alt][]}}:{{ports[http][0]}};"> 5 <meta http-equiv="Content-Security-Policy" content="script-src * 'unsafe-inline'; media-src 'self' {{hosts[alt][]}}:{{ports[http][0]}};"> 6 6 <script src='/resources/testharness.js'></script> 7 7 <script src='/resources/testharnessreport.js'></script> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/media-src/media-src-blocked.sub.html
r246330 r279838 28 28 assert_true(e.blockedURI == a_mediaURL || e.blockedURI == v_mediaURL, "Unexpected blockedURI"); 29 29 if (--test_count <= 0) { 30 t_spv.done(); 30 t_spv.done(); 31 31 } 32 32 })); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/meta/meta-outside-head.sub.html
r246330 r279838 19 19 alert_assert("Fail"); 20 20 }); 21 </script> 21 </script> 22 22 23 23 <meta http-equiv="Content-Security-Policy" content="script-src 'self'"> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/navigate-to/anchor-navigation-always-allowed.html
r246330 r279838 12 12 <script> 13 13 var t = async_test("Test that anchor navigation is allowed regardless of the `navigate-to` directive"); 14 14 15 15 window.addEventListener('securitypolicyviolation', t.unreached_func("Should not have triggered any violation")); 16 16 17 17 try { 18 18 window.location.hash = "anchor"; -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/navigate-to/parent-navigates-child-blocked.html.sub.headers
r246330 r279838 3 3 Pragma: no-cache 4 4 Set-Cookie: parent-navigates-child-blocked={{$id:uuid()}}; Path=/content-security-policy/navigate-to/ 5 Content-Security-Policy: navigate-to support/wait_for_navigation.html; report-uri ../support/report.py?op=put&reportID={{$id}}5 Content-Security-Policy: navigate-to support/wait_for_navigation.html; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/navigate-to/support/delayed_frame.py
r246330 r279838 2 2 def main(request, response): 3 3 time.sleep(1) 4 headers = [( "Content-Type","text/html")]5 return headers, '''4 headers = [(b"Content-Type", b"text/html")] 5 return headers, u''' 6 6 <!DOCTYPE html> 7 7 <head> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/navigate-to/support/form_action_navigation.sub.html
r246330 r279838 28 28 } 29 29 } catch(ex) {} 30 30 31 31 document.getElementById('form').submit(); 32 32 </script> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/navigate-to/support/form_action_navigation.sub.html.sub.headers
r246330 r279838 2 2 Cache-Control: no-store, no-cache, must-revalidate 3 3 Pragma: no-cache 4 Content-Security-Policy: {{GET[csp]}}; report-uri / content-security-policy/support/report.py?op=put&reportID={{GET[report_id]}}4 Content-Security-Policy: {{GET[csp]}}; report-uri /reporting/resources/report.py?op=put&reportID={{GET[report_id]}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/navigate-to/support/href_location_navigation.sub.html.sub.headers
r246330 r279838 2 2 Cache-Control: no-store, no-cache, must-revalidate 3 3 Pragma: no-cache 4 Content-Security-Policy: {{GET[csp]}}; report-uri / content-security-policy/support/report.py?op=put&reportID={{GET[report_id]}}4 Content-Security-Policy: {{GET[csp]}}; report-uri /reporting/resources/report.py?op=put&reportID={{GET[report_id]}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/navigate-to/support/link_click_navigation.sub.html.sub.headers
r246330 r279838 2 2 Cache-Control: no-store, no-cache, must-revalidate 3 3 Pragma: no-cache 4 Content-Security-Policy: {{GET[csp]}}; report-uri / content-security-policy/support/report.py?op=put&reportID={{GET[report_id]}}4 Content-Security-Policy: {{GET[csp]}}; report-uri /reporting/resources/report.py?op=put&reportID={{GET[report_id]}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/navigate-to/support/meta_refresh_navigation.sub.html.sub.headers
r246330 r279838 2 2 Cache-Control: no-store, no-cache, must-revalidate 3 3 Pragma: no-cache 4 Content-Security-Policy: {{GET[csp]}}; report-uri / content-security-policy/support/report.py?op=put&reportID={{GET[report_id]}}4 Content-Security-Policy: {{GET[csp]}}; report-uri /reporting/resources/report.py?op=put&reportID={{GET[report_id]}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/navigate-to/support/navigate_parent.sub.html.sub.headers
r246330 r279838 2 2 Cache-Control: no-store, no-cache, must-revalidate 3 3 Pragma: no-cache 4 Content-Security-Policy: {{GET[csp]}}; report-uri / content-security-policy/support/report.py?op=put&reportID={{GET[report_id]}}4 Content-Security-Policy: {{GET[csp]}}; report-uri /reporting/resources/report.py?op=put&reportID={{GET[report_id]}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/navigate-to/support/redirect_to_post_message_to_frame_owner.py
r246330 r279838 1 1 def main(request, response): 2 2 response.status = 302 3 if "location" in request.GET:4 response.headers.set( "Location", request.GET["location"])3 if b"location" in request.GET: 4 response.headers.set(b"Location", request.GET[b"location"]) 5 5 else: 6 response.headers.set( "Location","post_message_to_frame_owner.html")6 response.headers.set(b"Location", b"post_message_to_frame_owner.html") -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/navigate-to/support/spv-test-iframe1.sub.html.sub.headers
r246330 r279838 2 2 Cache-Control: no-store, no-cache, must-revalidate 3 3 Pragma: no-cache 4 Content-Security-Policy: navigate-to {{location[server]}}/content-security-policy/navigate-to/support/spv-test-iframe3.sub.html 'unsafe-allow-redirects'; report-uri / content-security-policy/support/report.py?op=put&reportID={{GET[report_id]}}4 Content-Security-Policy: navigate-to {{location[server]}}/content-security-policy/navigate-to/support/spv-test-iframe3.sub.html 'unsafe-allow-redirects'; report-uri /reporting/resources/report.py?op=put&reportID={{GET[report_id]}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/navigation/javascript-url-navigation-inherits-csp-expected.txt
r262312 r279838 1 1 2 FAIL Violation report status OK. assert_true: violated-directive value of "default-src 'none'" did not match frame-src. expected true got false 3 -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/navigation/support/test_csp_self_window.sub.html
r246330 r279838 3 3 <script src="/resources/testharnessreport.js"></script> 4 4 5 <span id="escape">{{GET[window_url]}}</span> 6 5 7 <script> 6 var window_url = d ecodeURIComponent("{{GET[window_url]}}").replace('<', '<').replace('>', '>');8 var window_url = document.getElementById("escape").textContent; 7 9 window.open(window_url, "_self"); 8 10 </script> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/navigation/support/test_csp_self_window.sub.html.sub.headers
r246330 r279838 4 4 Pragma: no-cache 5 5 Set-Cookie: {{GET[report_cookie_name]}}={{$id:uuid()}}; Path=/content-security-policy/navigation/ 6 Content-Security-Policy: default-src 'none'; script-src 'self' 'unsafe-inline'; report-uri ../../support/report.py?op=put&reportID={{$id}}6 Content-Security-Policy: default-src 'none'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/navigation/to-javascript-url-frame-src.html
r246330 r279838 9 9 <script> 10 10 var t = async_test("<iframe src='javascript:...'> not blocked by 'frame-src'"); 11 11 12 12 var i = document.createElement('iframe'); 13 13 i.src = "javascript:window.top.t.done();"; -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/object-src/object-src-no-url-allowed.html
r246330 r279838 5 5 <script src="/resources/testharness.js"></script> 6 6 <script src="/resources/testharnessreport.js"></script> 7 <!-- Content-Security-Policy: object-src 'self'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}} -->7 <!-- Content-Security-Policy: object-src 'self'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} --> 8 8 </head> 9 9 -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/object-src/object-src-no-url-allowed.html.sub.headers
r246330 r279838 1 1 Set-Cookie: object-src-no-url-allowed={{$id:uuid()}}; Path=/content-security-policy/object-src/ 2 Content-Security-Policy: object-src 'self'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}}2 Content-Security-Policy: object-src 'self'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/object-src/object-src-url-allowed.html
r263605 r279838 9 9 object-src 'self'; 10 10 script-src 'self' 'unsafe-inline'; 11 report-uri ../support/report.py?op=put&reportID={{$id}}11 report-uri /reporting/resources/report.py?op=put&reportID={{$id}} 12 12 --> 13 13 </head> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/object-src/object-src-url-allowed.html.sub.headers
r246330 r279838 1 1 Set-Cookie: object-src-url-allowed={{$id:uuid()}}; Path=/content-security-policy/object-src/ 2 Content-Security-Policy: object-src 'self'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}}2 Content-Security-Policy: object-src 'self'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/object-src/object-src-url-embed-allowed.html
r263605 r279838 9 9 object-src 'self'; 10 10 script-src 'self' 'unsafe-inline'; 11 report-uri ../support/report.py?op=put&reportID={{$id}}11 report-uri /reporting/resources/report.py?op=put&reportID={{$id}} 12 12 --> 13 13 </head> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/object-src/object-src-url-embed-allowed.html.sub.headers
r246330 r279838 1 1 Set-Cookie: object-src-url-embed-allowed={{$id:uuid()}}; Path=/content-security-policy/object-src/ 2 Content-Security-Policy: object-src 'self'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}}2 Content-Security-Policy: object-src 'self'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/object-src/object-src-url-redirect-allowed.html
r246330 r279838 5 5 <script src="/resources/testharness.js"></script> 6 6 <script src="/resources/testharnessreport.js"></script> 7 <!-- Content-Security-Policy: object-src 'self'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}} -->7 <!-- Content-Security-Policy: object-src 'self'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} --> 8 8 </head> 9 9 -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/object-src/object-src-url-redirect-allowed.html.sub.headers
r246330 r279838 1 1 Set-Cookie: object-src-url-redirect-allowed={{$id:uuid()}}; Path=/content-security-policy/object-src/ 2 Content-Security-Policy: object-src 'self'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}}2 Content-Security-Policy: object-src 'self'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/plugin-types/w3c-import.log
r246330 r279838 15 15 ------------------------------------------------------------------------ 16 16 List of files: 17 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-empty.sub.html 18 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-mismatched-data.html 19 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-mismatched-url.html 20 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-notype-data.html 21 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-notype-url.html 22 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-nourl-allowed.html 23 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-nourl-allowed.html.sub.headers 24 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-nourl-blocked.html 17 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugin-types-ignored.html 18 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugin-types-ignored.html.sub.headers -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-allowed.html
r246330 r279838 11 11 'file-prefetch-allowed.html'); 12 12 win.addEventListener('load', function () { 13 // Cache control headers are added,since they are needed 13 // Cache control headers are added,since they are needed 14 14 // to enable prefetching. 15 15 let url = '/content-security-policy/support/pass.png' + -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-header-allowed.html
r246330 r279838 16 16 17 17 waitUntilResourceDownloaded(url) 18 .then(t.step_func_done()); 18 .then(t.step_func_done()); 19 19 }, 'Prefetch via `Link` header succeeds when allowed by prefetch-src'); 20 20 </script> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-header-blocked.html
r246330 r279838 2 2 <html> 3 3 <head> 4 <meta http-equiv="Content-Security-Policy" content="prefetch-src 'none'"> 4 <!-- Headers: 5 Content-Security-Policy: prefetch-src 'none' 6 Link: </content-security-policy/support/fail.png>;rel=prefetch 7 --> 5 8 <script src='/resources/testharness.js'></script> 6 9 <script src='/resources/testharnessreport.js'></script> … … 13 16 .then(t.step_func_done(e => { 14 17 assert_equals(e.violatedDirective, 'prefetch-src'); 18 19 // This assert verifies both that the resource wasn't downloaded 20 // when prefetched via `Link` on both this document itself, and 21 // on the stylesheet subresource below. 15 22 assert_resource_not_downloaded(t, url); 16 23 })); 17 24 18 // Load a stylesheet that tries to trigger a prefetch:19 let link = document.createElement('link');20 link.rel = 'stylesheet';21 link.href = '/content-security-policy/support/prefetch-subresource.css';22 document.head.appendChild(link);23 }, 'Prefetch via `Link` header succeedswhen allowed by prefetch-src');25 // Load a stylesheet that tries to trigger a prefetch: 26 let link = document.createElement('link'); 27 link.rel = 'stylesheet'; 28 link.href = '/content-security-policy/support/prefetch-subresource.css'; 29 document.head.appendChild(link); 30 }, 'Prefetch via `Link` header blocked when allowed by prefetch-src'); 24 31 </script> 25 32 </head> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/prefetch-src/w3c-import.log
r246330 r279838 16 16 List of files: 17 17 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-allowed.html 18 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-blocked-by-default.html 18 19 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-blocked.html 19 20 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-header-allowed.html 20 21 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-header-allowed.html.headers 22 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-header-blocked-by-default.html 23 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-header-blocked-by-default.html.headers 21 24 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-header-blocked.html 25 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-header-blocked.html.headers -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-doesnt-send-reports-without-violation.https.sub.html.sub.headers
r246330 r279838 4 4 Pragma: no-cache 5 5 Set-Cookie: reporting-api-doesnt-send-reports-without-violation={{$id:uuid()}}; Path=/content-security-policy/reporting-api 6 Report-To: { "group": "csp-group", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/ content-security-policy/support/report.py?op=put&reportID={{$id}}" }] }6 Report-To: { "group": "csp-group", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/reporting/resources/report.py?op=put&reportID={{$id}}" }] } 7 7 Content-Security-Policy: script-src 'self' 'unsafe-inline'; img-src 'self'; report-to csp-group -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-report-only-sends-reports-on-violation.https.sub.html.sub.headers
r246330 r279838 4 4 Pragma: no-cache 5 5 Set-Cookie: reporting-api-report-only-sends-reports-on-violation={{$id:uuid()}}; Path=/content-security-policy/reporting-api 6 Report-To: { "group": "csp-group", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/ content-security-policy/support/report.py?op=put&reportID={{$id}}" }] }6 Report-To: { "group": "csp-group", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/reporting/resources/report.py?op=put&reportID={{$id}}" }] } 7 7 Content-Security-Policy-Report-Only: script-src 'self' 'unsafe-inline'; img-src 'none'; report-to csp-group -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-report-to-only-sends-reports-to-first-endpoint.https.sub.html.sub.headers
r263605 r279838 5 5 Set-Cookie: reporting-api-report-to-only-sends-reports-to-first-endpoint={{$id:uuid()}}; Path=/content-security-policy/reporting-api 6 6 Content-Security-Policy: script-src 'self' 'unsafe-inline'; img-src 'none'; report-to csp-group csp-group-2 7 Report-To: { "group": "csp-group", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/ content-security-policy/support/report.py?op=put&reportID={{uuid()}}" }] }, { "group": "csp-group-2", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/content-security-policy/support/report.py?op=put&reportID={{$id}}" }] }7 Report-To: { "group": "csp-group", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/reporting/resources/report.py?op=put&reportID={{uuid()}}" }] }, { "group": "csp-group-2", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/reporting/resources/report.py?op=put&reportID={{$id}}" }] } -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-report-to-overrides-report-uri-1.https.sub.html.sub.headers
r246330 r279838 4 4 Pragma: no-cache 5 5 Set-Cookie: reporting-api-report-to-overrides-report-uri-1={{$id:uuid()}}; Path=/content-security-policy/reporting-api 6 Content-Security-Policy: script-src 'self' 'unsafe-inline'; img-src 'none'; report-uri "/ content-security-policy/support/report.py?op=put&reportID={{$id}}"; report-to csp-group7 Report-To: { "group": "csp-group", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/ content-security-policy/support/report.py?op=put&reportID={{$id:uuid()}}" }] }6 Content-Security-Policy: script-src 'self' 'unsafe-inline'; img-src 'none'; report-uri "/reporting/resources/report.py?op=put&reportID={{$id}}"; report-to csp-group 7 Report-To: { "group": "csp-group", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/reporting/resources/report.py?op=put&reportID={{$id:uuid()}}" }] } -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-report-to-overrides-report-uri-2.https.sub.html.sub.headers
r246330 r279838 4 4 Pragma: no-cache 5 5 Set-Cookie: reporting-api-report-to-overrides-report-uri-2={{$id:uuid()}}; Path=/content-security-policy/reporting-api 6 Content-Security-Policy: script-src 'self' 'unsafe-inline'; img-src 'none'; report-to csp-group; report-uri "/ content-security-policy/support/report.py?op=put&reportID={{$id}}"7 Report-To: { "group": "csp-group", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/ content-security-policy/support/report.py?op=put&reportID={{$id:uuid()}}" }] }6 Content-Security-Policy: script-src 'self' 'unsafe-inline'; img-src 'none'; report-to csp-group; report-uri "/reporting/resources/report.py?op=put&reportID={{$id}}" 7 Report-To: { "group": "csp-group", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/reporting/resources/report.py?op=put&reportID={{$id:uuid()}}" }] } -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-sends-reports-on-violation.https.sub.html
r263605 r279838 37 37 assert_equals(reports[0].body.sample, ""); 38 38 assert_equals(reports[0].body.disposition, "enforce"); 39 assert_equals(reports[0].body.statusCode, 0);39 assert_equals(reports[0].body.statusCode, 200); 40 40 assert_equals(reports[0].body.lineNumber, 53); 41 41 assert_equals(reports[0].body.columnNumber, 0); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-sends-reports-on-violation.https.sub.html.sub.headers
r246330 r279838 4 4 Pragma: no-cache 5 5 Set-Cookie: reporting-api-sends-reports-on-violation={{$id:uuid()}}; Path=/content-security-policy/reporting-api 6 Report-To: { "group": "csp-group", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/ content-security-policy/support/report.py?op=put&reportID={{$id}}" }] }6 Report-To: { "group": "csp-group", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/reporting/resources/report.py?op=put&reportID={{$id}}" }] } 7 7 Content-Security-Policy: script-src 'self' 'unsafe-inline'; img-src 'none'; report-to csp-group -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-works-on-frame-src.https.sub.html.sub.headers
r246330 r279838 3 3 Pragma: no-cache 4 4 Set-Cookie: reporting-api-works-on-frame-src={{$id:uuid()}}; Path=/content-security-policy/reporting-api 5 Report-To: { "group": "csp-group", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/ content-security-policy/support/report.py?op=put&reportID={{$id}}" }] }5 Report-To: { "group": "csp-group", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/reporting/resources/report.py?op=put&reportID={{$id}}" }] } 6 6 Content-Security-Policy: script-src 'self' 'unsafe-inline'; frame-src 'none'; report-to csp-group -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/w3c-import.log
r263605 r279838 15 15 ------------------------------------------------------------------------ 16 16 List of files: 17 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/report-to-directive-allowed-in-meta.https.sub.html 18 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/report-to-directive-allowed-in-meta.https.sub.html.sub.headers 17 19 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-doesnt-send-reports-without-violation.https.sub.html 18 20 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-doesnt-send-reports-without-violation.https.sub.html.sub.headers … … 27 29 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-sends-reports-on-violation.https.sub.html 28 30 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-sends-reports-on-violation.https.sub.html.sub.headers 31 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-works-on-frame-ancestors.https.sub.html 32 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-works-on-frame-ancestors.https.sub.html.sub.headers 29 33 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-works-on-frame-src.https.sub.html 30 34 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-works-on-frame-src.https.sub.html.sub.headers -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/multiple-report-policies.html
r246330 r279838 6 6 <title>When multiple report-uri endpoints for multiple policies are specified, each gets a report</title> 7 7 <!-- CSP headers 8 Content-Security-Policy-Report-Only: img-src http://* https://*; default-src 'self'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}}8 Content-Security-Policy-Report-Only: img-src http://* https://*; default-src 'self'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} 9 9 10 Content-Security-Policy-Report-Only: img-src http://*; default-src 'self'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}}10 Content-Security-Policy-Report-Only: img-src http://*; default-src 'self'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} 11 11 --> 12 12 </head> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/multiple-report-policies.html.sub.headers
r246330 r279838 4 4 Pragma: no-cache 5 5 Set-Cookie: multiple-report-policies={{$id:uuid()}}; Path=/content-security-policy/reporting/ 6 Content-Security-Policy-Report-Only: img-src http://* https://*; default-src 'self'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}}6 Content-Security-Policy-Report-Only: img-src http://* https://*; default-src 'self'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} 7 7 Set-Cookie: multiple-report-policies-2={{$id:uuid()}}; Path=/content-security-policy/reporting/ 8 Content-Security-Policy-Report-Only: img-src http://*; default-src 'self'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}}8 Content-Security-Policy-Report-Only: img-src http://*; default-src 'self'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/post-redirect-stacktrace.https.html
r263605 r279838 14 14 15 15 const blank_path = "/common/blank.html" 16 const redirect = url => 16 const redirect = url => 17 17 `/content-security-policy/reporting/support/redirect-throw-function.sub.py?token=${token()}`; 18 18 -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-and-enforce.html
r246330 r279838 8 8 Content-Security-Policy: img-src 'none'; style-src *; script-src 'self' 'unsafe-inline' 9 9 10 Content-Security-Policy-Report-Only: img-src *; style-src 'none'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}}10 Content-Security-Policy-Report-Only: img-src *; style-src 'none'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} 11 11 --> 12 12 </head> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-and-enforce.html.sub.headers
r246330 r279838 5 5 Set-Cookie: report-and-enforce={{$id:uuid()}}; Path=/content-security-policy/reporting/ 6 6 Content-Security-Policy: img-src 'none'; style-src *; script-src 'self' 'unsafe-inline' 7 Content-Security-Policy-Report-Only: img-src *; style-src 'none'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}}7 Content-Security-Policy-Report-Only: img-src *; style-src 'none'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-blocked-data-uri.html
r246330 r279838 6 6 <title>Data-uri images are reported correctly</title> 7 7 <!-- CSP headers 8 Content-Security-Policy: img-src 'none'; report-uri ../support/report.py?op=put&reportID={{$id}}8 Content-Security-Policy: img-src 'none'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} 9 9 --> 10 10 </head> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-blocked-data-uri.html.sub.headers
r246330 r279838 4 4 Pragma: no-cache 5 5 Set-Cookie: report-blocked-data-uri={{$id:uuid()}}; Path=/content-security-policy/reporting/ 6 Content-Security-Policy: img-src 'none'; report-uri ../support/report.py?op=put&reportID={{$id}}6 Content-Security-Policy: img-src 'none'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-blocked-uri-cross-origin.sub.html
r246330 r279838 7 7 <!-- CSP headers 8 8 Content-Security-Policy: script-src 'self' 'unsafe-inline' 9 Content-Security-Policy-Report-Only: img-src 'none'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID=$id9 Content-Security-Policy-Report-Only: img-src 'none'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID=$id 10 10 --> 11 11 </head> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-blocked-uri-cross-origin.sub.html.sub.headers
r246330 r279838 5 5 Set-Cookie: report-blocked-uri-cross-origin={{$id:uuid()}}; Path=/content-security-policy/reporting/ 6 6 Content-Security-Policy: script-src 'self' 'unsafe-inline' 7 Content-Security-Policy-Report-Only: img-src 'none'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}}7 Content-Security-Policy-Report-Only: img-src 'none'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-blocked-uri.html
r246330 r279838 7 7 <!-- CSP headers 8 8 Content-Security-Policy: script-src 'self' 'unsafe-inline' 9 Content-Security-Policy-Report-Only: img-src 'none'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}}9 Content-Security-Policy-Report-Only: img-src 'none'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} 10 10 --> 11 11 </head> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-blocked-uri.html.sub.headers
r246330 r279838 5 5 Set-Cookie: report-blocked-uri={{$id:uuid()}}; Path=/content-security-policy/reporting/ 6 6 Content-Security-Policy: script-src 'self' 'unsafe-inline' 7 Content-Security-Policy-Report-Only: img-src 'none'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}}7 Content-Security-Policy-Report-Only: img-src 'none'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-cross-origin-no-cookies.sub.html
r254133 r279838 7 7 <script src="/resources/testharnessreport.js"></script> 8 8 <!-- CSP headers 9 Content-Security-Policy: script-src 'unsafe-inline' 'self'; img-src 'none'; report-uri http://{{domains[www1]}}:{{ports[http][0]}}/ content-security-policy/support/report.py?op=put&reportID=$id9 Content-Security-Policy: script-src 'unsafe-inline' 'self'; img-src 'none'; report-uri http://{{domains[www1]}}:{{ports[http][0]}}/reporting/resources/report.py?op=put&reportID=$id 10 10 --> 11 11 </head> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-cross-origin-no-cookies.sub.html.sub.headers
r246330 r279838 4 4 Pragma: no-cache 5 5 Set-Cookie: report-cross-origin-no-cookies={{$id:uuid()}}; Path=/content-security-policy/reporting/ 6 Content-Security-Policy: script-src 'unsafe-inline' 'self'; img-src 'none'; report-uri http://{{domains[www1]}}:{{ports[http][0]}}/ content-security-policy/support/report.py?op=put&reportID={{$id}}6 Content-Security-Policy: script-src 'unsafe-inline' 'self'; img-src 'none'; report-uri http://{{domains[www1]}}:{{ports[http][0]}}/reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-multiple-violations-01.html
r246330 r279838 6 6 <title>Test multiple violations cause multiple reports</title> 7 7 <!-- CSP headers 8 Content-Security-Policy-Report-Only: script-src 'unsafe-inline' 'self'; img-src 'none'; report-uri ../support/report.py?op=put&reportID={{$id}}8 Content-Security-Policy-Report-Only: script-src 'unsafe-inline' 'self'; img-src 'none'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} 9 9 --> 10 10 </head> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-multiple-violations-01.html.sub.headers
r246330 r279838 4 4 Pragma: no-cache 5 5 Set-Cookie: report-multiple-violations-01={{$id:uuid()}}; Path=/content-security-policy/reporting/ 6 Content-Security-Policy-Report-Only: script-src 'unsafe-inline' 'self'; img-src 'none'; report-uri ../support/report.py?op=put&reportID={{$id}}6 Content-Security-Policy-Report-Only: script-src 'unsafe-inline' 'self'; img-src 'none'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-multiple-violations-02.html
r246330 r279838 7 7 if and only if the violations are distinct.</title> 8 8 <!-- CSP headers 9 Content-Security-Policy-Report-Only: script-src 'unsafe-inline' 'self'; report-uri ../support/report.py?op=put&reportID={{$id}}9 Content-Security-Policy-Report-Only: script-src 'unsafe-inline' 'self'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} 10 10 --> 11 11 </head> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-multiple-violations-02.html.sub.headers
r246330 r279838 4 4 Pragma: no-cache 5 5 Set-Cookie: report-multiple-violations-02={{$id:uuid()}}; Path=/content-security-policy/reporting/ 6 Content-Security-Policy-Report-Only: script-src 'unsafe-inline' 'self'; report-uri ../support/report.py?op=put&reportID={{$id}}6 Content-Security-Policy-Report-Only: script-src 'unsafe-inline' 'self'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-only-in-meta.sub.html
r254133 r279838 10 10 --> 11 11 <!-- since we try to set the report-uri in the meta tag, we have to set the cookie with the reportID in here instead of in the headers file --> 12 <meta http-equiv="Content-Security-Policy-Report-Only" content="img-src 'none'; report-uri ../support/report.py?op=put&reportID={{$id:uuid()}}">12 <meta http-equiv="Content-Security-Policy-Report-Only" content="img-src 'none'; report-uri /reporting/resources/report.py?op=put&reportID={{$id:uuid()}}"> 13 13 </head> 14 14 <body> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-only-unsafe-eval.html
r254133 r279838 5 5 <script nonce='abc' src="/resources/testharnessreport.js"></script> 6 6 <!-- CSP headers 7 Content-Security-Policy-Report-Only: script-src 'unsafe-inline' 'nonce-abc'; report-uri ../support/report.py?op=put&reportID={{$id}}7 Content-Security-Policy-Report-Only: script-src 'unsafe-inline' 'nonce-abc'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} 8 8 --> 9 9 </head> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-only-unsafe-eval.html.sub.headers
r254133 r279838 2 2 Pragma: no-cache 3 3 Set-Cookie: report-only-unsafe-eval={{$id:uuid()}}; Path=/content-security-policy/reporting/ 4 Content-Security-Policy-Report-Only: script-src 'unsafe-inline' 'nonce-abc'; report-uri ../support/report.py?op=put&reportID={{$id}}4 Content-Security-Policy-Report-Only: script-src 'unsafe-inline' 'nonce-abc'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-original-url-on-mixed-content-frame.https.sub.html.sub.headers
r263605 r279838 4 4 Pragma: no-cache 5 5 Set-Cookie: report-original-url-on-mixed-content-frame={{$id:uuid()}}; Path=/content-security-policy/reporting/ 6 Content-Security-Policy: block-all-mixed-content; report-uri ../support/report.py?op=put&reportID={{$id}}6 Content-Security-Policy: block-all-mixed-content; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-original-url.sub.html
r263605 r279838 5 5 <script src="/resources/testharnessreport.js"></script> 6 6 <!-- CSP headers 7 Content-Security-Policy: img-src {{location[scheme]}}://{{domains[www1]}}:{{ports[http][0]}}; script-src 'unsafe-inline' 'self'; report-uri ../support/report.py?op=put&reportID=$id7 Content-Security-Policy: img-src {{location[scheme]}}://{{domains[www1]}}:{{ports[http][0]}}; script-src 'unsafe-inline' 'self'; report-uri /reporting/resources/report.py?op=put&reportID=$id 8 8 --> 9 9 </head> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-original-url.sub.html.sub.headers
r246330 r279838 4 4 Pragma: no-cache 5 5 Set-Cookie: report-original-url={{$id:uuid()}}; Path=/content-security-policy/reporting/ 6 Content-Security-Policy: img-src {{location[scheme]}}://{{domains[www1]}}:{{ports[http][0]}}; script-src 'unsafe-inline' 'self'; report-uri ../support/report.py?op=put&reportID={{$id}}6 Content-Security-Policy: img-src {{location[scheme]}}://{{domains[www1]}}:{{ports[http][0]}}; script-src 'unsafe-inline' 'self'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-same-origin-with-cookies.html
r246330 r279838 6 6 <title>Cookies are sent on same origin violation reports</title> 7 7 <!-- CSP headers 8 Content-Security-Policy: script-src 'unsafe-inline' 'self'; img-src 'none'; report-uri / content-security-policy/support/report.py?op=put&reportID={{$id}}8 Content-Security-Policy: script-src 'unsafe-inline' 'self'; img-src 'none'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} 9 9 --> 10 10 </head> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-same-origin-with-cookies.html.sub.headers
r246330 r279838 4 4 Pragma: no-cache 5 5 Set-Cookie: report-same-origin-with-cookies={{$id:uuid()}}; Path=/content-security-policy/reporting/ 6 Content-Security-Policy: script-src 'unsafe-inline' 'self'; img-src 'none'; report-uri / content-security-policy/support/report.py?op=put&reportID={{$id}}6 Content-Security-Policy: script-src 'unsafe-inline' 'self'; img-src 'none'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-effective-directive.html
r246330 r279838 6 6 <title>Violation report is sent if violation occurs.</title> 7 7 <!-- CSP headers 8 Content-Security-Policy: default-src 'self'; report-uri ../support/report.py?op=put&reportID={{$id}}8 Content-Security-Policy: default-src 'self'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} 9 9 --> 10 10 </head> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-effective-directive.html.sub.headers
r246330 r279838 4 4 Pragma: no-cache 5 5 Set-Cookie: report-uri-effective-directive={{$id:uuid()}}; Path=/content-security-policy/reporting/ 6 Content-Security-Policy: default-src 'self'; report-uri ../support/report.py?op=put&reportID={{$id}}6 Content-Security-Policy: default-src 'self'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-from-inline-javascript.html
r246330 r279838 6 6 <title>Violation report is sent from inline javascript.</title> 7 7 <!-- CSP headers 8 Content-Security-Policy: img-src 'none'; report-uri ../support/report.py?op=put&reportID={{$id}}8 Content-Security-Policy: img-src 'none'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} 9 9 --> 10 10 </head> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-from-inline-javascript.html.sub.headers
r246330 r279838 4 4 Pragma: no-cache 5 5 Set-Cookie: report-uri-from-inline-javascript={{$id:uuid()}}; Path=/content-security-policy/reporting/ 6 Content-Security-Policy: img-src 'none'; report-uri ../support/report.py?op=put&reportID={{$id}}6 Content-Security-Policy: img-src 'none'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-from-javascript.html
r246330 r279838 6 6 <title>Violation report is sent from javascript resource.</title> 7 7 <!-- CSP headers 8 Content-Security-Policy: img-src 'none'; report-uri ../support/report.py?op=put&reportID={{$id}}8 Content-Security-Policy: img-src 'none'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} 9 9 --> 10 10 </head> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-from-javascript.html.sub.headers
r246330 r279838 4 4 Pragma: no-cache 5 5 Set-Cookie: report-uri-from-javascript={{$id:uuid()}}; Path=/content-security-policy/reporting/ 6 Content-Security-Policy: img-src 'none'; report-uri ../support/report.py?op=put&reportID={{$id}}6 Content-Security-Policy: img-src 'none'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-multiple-reversed.html
r246330 r279838 6 6 <title>Content-Security-Policy-Report-Only violation report is sent even when resource is blocked by actual policy.</title> 7 7 <!-- CSP headers 8 Content-Security-Policy-Report-Only: img-src http://*; report-uri ../support/report.py?op=put&reportID={{$id}}8 Content-Security-Policy-Report-Only: img-src http://*; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} 9 9 Content-Security-Policy: img-src http://* 10 10 --> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-multiple-reversed.html.sub.headers
r246330 r279838 4 4 Pragma: no-cache 5 5 Set-Cookie: report-uri-multiple-reversed={{$id:uuid()}}; Path=/content-security-policy/reporting/ 6 Content-Security-Policy-Report-Only: img-src http://*; report-uri ../support/report.py?op=put&reportID={{$id}}6 Content-Security-Policy-Report-Only: img-src http://*; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} 7 7 Content-Security-Policy: img-src http://* -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-multiple.html
r246330 r279838 7 7 <!-- CSP headers 8 8 Content-Security-Policy: img-src http://* 9 Content-Security-Policy-Report-Only: img-src http://*; report-uri ../support/report.py?op=put&reportID={{$id}}9 Content-Security-Policy-Report-Only: img-src http://*; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} 10 10 --> 11 11 </head> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-multiple.html.sub.headers
r246330 r279838 5 5 Set-Cookie: report-uri-multiple={{$id:uuid()}}; Path=/content-security-policy/reporting/ 6 6 Content-Security-Policy: img-src http://* 7 Content-Security-Policy-Report-Only: img-src http://*; report-uri ../support/report.py?op=put&reportID={{$id}}7 Content-Security-Policy-Report-Only: img-src http://*; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-scheme-relative.html
r246330 r279838 6 6 <title>Relative scheme URIs are accepted as the report-uri.</title> 7 7 <!-- CSP headers 8 Content-Security-Policy: script-src 'self'; report-uri //{{location[host]}}/ content-security-policy/support/report.py?op=put&reportID={{$id}}8 Content-Security-Policy: script-src 'self'; report-uri //{{location[host]}}/reporting/resources/report.py?op=put&reportID={{$id}} 9 9 --> 10 10 </head> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-scheme-relative.html.sub.headers
r246330 r279838 4 4 Pragma: no-cache 5 5 Set-Cookie: report-uri-scheme-relative={{$id:uuid()}}; Path=/content-security-policy/reporting/ 6 Content-Security-Policy: script-src 'self'; report-uri //{{location[host]}}/ content-security-policy/support/report.py?op=put&reportID={{$id}}6 Content-Security-Policy: script-src 'self'; report-uri //{{location[host]}}/reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/support/generate-csp-report.html.sub.headers
r246330 r279838 4 4 Pragma: no-cache 5 5 Set-Cookie: generate-csp-report={{$id:uuid()}}; Path=/content-security-policy/reporting/ 6 Content-Security-Policy: script-src 'self' 'nonce-abc'; report-uri ../../support/report.py?op=put&reportID={{$id}}6 Content-Security-Policy: script-src 'self' 'nonce-abc'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/support/w3c-import.log
r263605 r279838 17 17 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/support/generate-csp-report.html 18 18 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/support/generate-csp-report.html.sub.headers 19 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/support/not-embeddable-frame.py 19 20 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/support/redirect-throw-function.sub.py 20 21 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/support/set-cookie.py -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/w3c-import.log
r263605 r279838 30 30 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-cross-origin-no-cookies.sub.html 31 31 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-cross-origin-no-cookies.sub.html.sub.headers 32 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-frame-ancestors-with-x-frame-options.sub.html 33 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-frame-ancestors.sub.html 32 34 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-multiple-violations-01.html 33 35 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-multiple-violations-01.html.sub.headers -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/support/w3c-import.log
r246330 r279838 15 15 ------------------------------------------------------------------------ 16 16 List of files: 17 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/support/empty.html 18 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/support/post-origin-on-load-worker.js 17 19 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/support/sandboxed-data-iframe.sub.html 18 20 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/support/sandboxed-data-iframe.sub.html.sub.headers … … 22 24 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/support/sandboxed-post-property-to-opener.html 23 25 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/support/sandboxed-post-property-to-opener.html.sub.headers 26 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/support/sandboxed-service-worker.js 27 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/support/sandboxed-service-worker.js.headers 28 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/support/sandboxed-shared-worker.js 29 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/support/sandboxed-shared-worker.js.headers 24 30 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/support/unsandboxed-post-property-to-opener.html -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/w3c-import.log
r246330 r279838 16 16 List of files: 17 17 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/iframe-inside-csp.sub.html 18 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/meta-element.sub.html 18 19 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/sandbox-allow-scripts-subframe.sub.html 19 20 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/sandbox-allow-scripts.sub.html 20 21 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/sandbox-empty-subframe.sub.html 21 22 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/sandbox-empty.sub.html 23 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/service-worker-sandbox.https.html 24 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/shared-worker-sandbox.html 22 25 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/window-reuse-sandboxed.html 23 26 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/window-reuse-unsandboxed.html -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/10_1_support_2.js
r246330 r279838 2 2 assert_true(dataScriptRan, "data script ran"); 3 3 }, "Verify that data: as script src runs with this policy"); 4 4 5 5 t_spv.done(); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/eval-allowed-in-report-only-mode-and-sends-report-expected.txt
r267651 r279838 1 1 2 2 PASS Eval is allowed because the CSP is report-only 3 PASS Violation report status OK. 3 FAIL Violation report status OK. undefined is not an object (evaluating 'data[0]["body"]') 4 4 -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/eval-allowed-in-report-only-mode-and-sends-report.html
r246330 r279838 3 3 <script src="/resources/testharness.js"></script> 4 4 <script src="/resources/testharnessreport.js"></script> 5 <!-- Content-Security-Policy-Report-Only: script-src 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}} -->5 <!-- Content-Security-Policy-Report-Only: script-src 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} --> 6 6 </head> 7 7 <body> … … 15 15 </script> 16 16 17 <script async defer src="../support/checkReport.sub.js?reportField= violated-directive&reportValue=script-src%20%27unsafe-inline%27"></script>17 <script async defer src="../support/checkReport.sub.js?reportField=blocked-uri&reportValue=eval"></script> 18 18 </body> 19 19 </html> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/eval-allowed-in-report-only-mode-and-sends-report.html.sub.headers
r246330 r279838 1 1 Set-Cookie: eval-allowed-in-report-only-mode-and-sends-report={{$id:uuid()}}; Path=/content-security-policy/script-src 2 Content-Security-Policy-Report-Only: script-src 'unsafe-inline' ; report-uri ../support/report.py?op=put&reportID={{$id}}2 Content-Security-Policy-Report-Only: script-src 'unsafe-inline' 'self'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/injected-inline-script-blocked.sub-expected.txt
r246330 r279838 1 1 2 FAIL Expecting logs: ["violated-directive=script-src-elem", ] assert_unreached: Logging timeout, expected logs violated-directive=script-src-elemnot sent. Reached unreachable code2 FAIL Expecting logs: ["violated-directive=script-src-elem","blocked-uri=inline"] assert_unreached: Logging timeout, expected logs violated-directive=script-src-elem,blocked-uri=inline not sent. Reached unreachable code 3 3 -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/injected-inline-script-blocked.sub.html
r246330 r279838 8 8 <script nonce='abc' src="/resources/testharness.js"></script> 9 9 <script nonce='abc' src="/resources/testharnessreport.js"></script> 10 <script nonce='abc' src='../support/logTest.sub.js?logs=["violated-directive=script-src-elem", ]'></script>10 <script nonce='abc' src='../support/logTest.sub.js?logs=["violated-directive=script-src-elem","blocked-uri=inline"]'></script> 11 11 <script nonce='abc' src='../support/alertAssert.sub.js?alerts=[]'></script> 12 12 </head> … … 16 16 window.addEventListener('securitypolicyviolation', function(e) { 17 17 log("violated-directive=" + e.violatedDirective); 18 log("blocked-uri=" + e.blockedURI); 18 19 }); 19 20 </script> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/javascript-window-open-blocked.html.sub.headers
r246330 r279838 4 4 Pragma: no-cache 5 5 Set-Cookie: javascript-window-open-blocked={{$id:uuid()}}; Path=/content-security-policy/script-src/ 6 Content-Security-Policy: script-src 'nonce-abc'; report-uri ../support/report.py?op=put&reportID={{$id}}6 Content-Security-Policy: script-src 'nonce-abc'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-1_10.html
r246330 r279838 14 14 var dataScriptRan = false; 15 15 var t_spv = async_test("Test that securitypolicyviolation event is fired"); 16 16 17 17 window.addEventListener("securitypolicyviolation", t_spv.step_func_done(function(e) { 18 assert_equals(e.violatedDirective, "script-src ");18 assert_equals(e.violatedDirective, "script-src-elem"); 19 19 })); 20 20 </script> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-1_4.html
r263605 r279838 13 13 <script> 14 14 var t_spv = async_test("Test that securitypolicyviolation event is fired"); 15 15 16 16 window.addEventListener("securitypolicyviolation", t_spv.step_func_done(function(e) { 17 17 assert_equals(e.violatedDirective, "script-src"); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-1_4_1.html
r246330 r279838 3 3 <head> 4 4 <title>setTimeout() and setInterval() should not run without 'unsafe-eval' script-src directive.</title> 5 <meta http-equiv="Content-Security-Policy" content="script-src 'self' 'unsafe-inline';"> 5 <meta http-equiv="Content-Security-Policy" content="script-src 'self' 'unsafe-inline';"> 6 6 <script src='/resources/testharness.js'></script> 7 7 <script src='/resources/testharnessreport.js'></script> … … 16 16 var t_spv = async_test("Test that securitypolicyviolation event is fired"); 17 17 var test_count = 2; 18 18 19 19 window.addEventListener("securitypolicyviolation", t_spv.step_func_done(function(e) { 20 20 assert_equals(e.violatedDirective, "script-src"); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-1_4_2.html
r263605 r279838 13 13 <script> 14 14 var t_spv = async_test("Test that securitypolicyviolation event is fired"); 15 15 16 16 window.addEventListener("securitypolicyviolation", t_spv.step_func_done(function(e) { 17 17 assert_equals(e.violatedDirective, "script-src"); 18 18 })); 19 19 20 20 21 21 test(function() { -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_eval.html
r263605 r279838 21 21 assert_false(evalScriptRan); 22 22 assert_equals(e.effectiveDirective, 'script-src'); 23 assert_equals(e.blockedURI, 'eval'); 23 24 })); 24 25 -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_hashes.html
r246330 r279838 7 7 <script src='/resources/testharnessreport.js' nonce='dummy'></script> 8 8 9 <!-- CSP served: script-src 'strict-dynamic' 'nonce-dummy' 'sha256-yU6Q7nD1TCBB9JvY06iIJ8ONLOPU4g8ml5JCDgXkv+M=' 'sha256- IFt1v6itHgqlrtInbPm/y7qyWcAlDbPgZM+92C5EZ5o=' -->9 <!-- CSP served: script-src 'strict-dynamic' 'nonce-dummy' 'sha256-yU6Q7nD1TCBB9JvY06iIJ8ONLOPU4g8ml5JCDgXkv+M=' 'sha256-EEoi70frWHkGFhK51NVIJkXpq72aPxSCNZEow37ZmRA=' --> 10 10 </head> 11 11 … … 17 17 var hashScriptRan = false; 18 18 window.addEventListener('securitypolicyviolation', function(e) { 19 assert_unreached(' No CSP violation report has fired.');19 assert_unreached('CSP violation reports should not fire.'); 20 20 }); 21 21 </script> 22 22 23 <!-- Hash: 'sha256- yU6Q7nD1TCBB9JvY06iIJ8ONLOPU4g8ml5JCDgXkv+M=' -->23 <!-- Hash: 'sha256-EEoi70frWHkGFhK51NVIJkXpq72aPxSCNZEow37ZmRA=' --> 24 24 <script> 25 25 hashScriptRan = true; -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_hashes.html.headers
r246330 r279838 3 3 Cache-Control: post-check=0, pre-check=0, false 4 4 Pragma: no-cache 5 Content-Security-Policy: script-src 'strict-dynamic' 'nonce-dummy' 'sha256-yU6Q7nD1TCBB9JvY06iIJ8ONLOPU4g8ml5JCDgXkv+M=' 'sha256- IFt1v6itHgqlrtInbPm/y7qyWcAlDbPgZM+92C5EZ5o='5 Content-Security-Policy: script-src 'strict-dynamic' 'nonce-dummy' 'sha256-yU6Q7nD1TCBB9JvY06iIJ8ONLOPU4g8ml5JCDgXkv+M=' 'sha256-EEoi70frWHkGFhK51NVIJkXpq72aPxSCNZEow37ZmRA=' -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/scripthash-allowed.sub.html
r246330 r279838 14 14 }); 15 15 </script> 16 16 17 17 <script> 18 18 alert_assert('PASS (1/4)'); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/scripthash-basic-blocked.sub.html
r246330 r279838 4 4 <head> 5 5 <!-- Programmatically converted from a WebKit Reftest, please forgive resulting idiosyncracies.--> 6 <meta http-equiv="Content-Security-Policy" content="script-src 'self' 'nonce-abc' 'sha256- k7iO9DPkNQ7PcwPP+8XyYuRiCJ0p76Ofveol9g3mFNs=' 'sha256-EgE/bwVJ+ZLL9F5hNjDqD4C7nlFFrdDaKeNIJ2cUem4='; connect-src 'self';">6 <meta http-equiv="Content-Security-Policy" content="script-src 'self' 'nonce-abc' 'sha256-3iveTSiUbmzN7COYvdDwyaXXzJ3SrjKlTaOvQ/GdRpo=' 'sha256-EgE/bwVJ+ZLL9F5hNjDqD4C7nlFFrdDaKeNIJ2cUem4='; connect-src 'self';"> 7 7 <title>scripthash-basic-blocked</title> 8 8 <script src="/resources/testharness.js"></script> … … 14 14 }); 15 15 </script> 16 16 17 17 <script> 18 18 var t_alert = async_test('Expecting alerts: ["PASS (1/1)"]'); … … 27 27 for (var i = 0; i < expected_alerts.length; i++) { 28 28 if (expected_alerts[i] == msg) { 29 assert_ true(expected_alerts[i] ==msg);29 assert_equals(expected_alerts[i], msg); 30 30 expected_alerts.splice(i, 1); 31 31 if (expected_alerts.length == 0) { -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/scripthash-default-src.sub.html
r253630 r279838 12 12 }); 13 13 </script> 14 14 15 15 <script>done();</script> 16 16 </head> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/scripthash-ignore-unsafeinline.sub.html
r246330 r279838 4 4 <head> 5 5 <!-- Programmatically converted from a WebKit Reftest, please forgive resulting idiosyncracies.--> 6 <meta http-equiv="Content-Security-Policy" content="script-src 'self' 'unsafe-inline' 'sha256- k7iO9DPkNQ7PcwPP+8XyYuRiCJ0p76Ofveol9g3mFNs=' 'sha256-EgE/bwVJ+ZLL9F5hNjDqD4C7nlFFrdDaKeNIJ2cUem4=' 'sha256-lxHfHAe5I15v8qaArcZ5WiKmLU4CjV+3tJeQUqSIWBk='; connect-src 'self';">7 6 <meta http-equiv="Content-Security-Policy" content="script-src 'self' 'unsafe-inline' 'sha256-3iveTSiUbmzN7COYvdDwyaXXzJ3SrjKlTaOvQ/GdRpo=' 'sha256-EgE/bwVJ+ZLL9F5hNjDqD4C7nlFFrdDaKeNIJ2cUem4=' 'sha256-lxHfHAe5I15v8qaArcZ5WiKmLU4CjV+3tJeQUqSIWBk='; connect-src 'self';"> 7 8 8 <title>scripthash-ignore-unsafeinline</title> 9 9 <script src="/resources/testharness.js"></script> … … 23 23 for (var i = 0; i < expected_alerts.length; i++) { 24 24 if (expected_alerts[i] == msg) { 25 assert_ true(expected_alerts[i] ==msg);25 assert_equals(expected_alerts[i], msg); 26 26 expected_alerts.splice(i, 1); 27 27 if (expected_alerts.length == 0) { -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/scriptnonce-allowed.sub.html
r246330 r279838 32 32 for (var i = 0; i < expected_alerts.length; i++) { 33 33 if (expected_alerts[i] == msg) { 34 assert_ true(expected_alerts[i] ==msg);34 assert_equals(expected_alerts[i], msg); 35 35 expected_alerts.splice(i, 1); 36 36 if (expected_alerts.length == 0) { -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/scriptnonce-and-scripthash.sub.html
r246330 r279838 31 31 for (var i = 0; i < expected_alerts.length; i++) { 32 32 if (expected_alerts[i] == msg) { 33 assert_ true(expected_alerts[i] ==msg);33 assert_equals(expected_alerts[i], msg); 34 34 expected_alerts.splice(i, 1); 35 35 if (expected_alerts.length == 0) { -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/scriptnonce-ignore-unsafeinline.sub.html
r246330 r279838 31 31 for (var i = 0; i < expected_alerts.length; i++) { 32 32 if (expected_alerts[i] == msg) { 33 assert_ true(expected_alerts[i] ==msg);33 assert_equals(expected_alerts[i], msg); 34 34 expected_alerts.splice(i, 1); 35 35 if (expected_alerts.length == 0) { -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/scriptnonce-redirect.sub.html
r246330 r279838 31 31 for (var i = 0; i < expected_alerts.length; i++) { 32 32 if (expected_alerts[i] == msg) { 33 assert_ true(expected_alerts[i] ==msg);33 assert_equals(expected_alerts[i], msg); 34 34 expected_alerts.splice(i, 1); 35 35 if (expected_alerts.length == 0) { -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/support/w3c-import.log
r254133 r279838 25 25 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/support/worker-function-function.js 26 26 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/support/worker-function-function.js.sub.headers 27 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/support/worker- importscripts.js28 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/support/worker- importscripts.js.sub.headers29 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/support/worker- set-timeout.js30 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/support/worker- set-timeout.js.sub.headers27 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/support/worker-with-script-src-none-importscripts.js 28 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/support/worker-with-script-src-none-importscripts.js.sub.headers 29 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/support/worker-with-script-src-none-set-timeout.js 30 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/support/worker-with-script-src-none-set-timeout.js.sub.headers -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/w3c-import.log
r263605 r279838 61 61 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_double_policy_different_nonce.html 62 62 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_double_policy_different_nonce.html.headers 63 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_double_policy_honor_source_expressions. html64 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_double_policy_honor_source_expressions. html.headers63 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_double_policy_honor_source_expressions.sub.html 64 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_double_policy_honor_source_expressions.sub.html.headers 65 65 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_double_policy_report_only.html 66 66 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_double_policy_report_only.html.headers … … 91 91 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/scripthash-basic-blocked-error-event.html 92 92 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/scripthash-basic-blocked.sub.html 93 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/scripthash-case-insensitive.sub.html 93 94 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/scripthash-changed-1.html 94 95 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/scripthash-changed-2.html … … 105 106 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/simpleSourcedScript.js 106 107 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/srcdoc-doesnt-bypass-script-src.sub.html 108 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/worker-data-set-timeout.sub.html 107 109 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/worker-eval-blocked.sub.html 108 110 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/worker-function-function-blocked.sub.html 109 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/worker-importscripts -blocked.sub.html111 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/worker-importscripts.sub.html 110 112 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/worker-script-src.sub.html 111 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/worker-set-timeout -blocked.sub.html113 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/worker-set-timeout.sub.html -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/worker-eval-blocked.sub.html
r246330 r279838 22 22 log('Fail'); 23 23 }); 24 24 25 25 try { 26 26 var worker = new Worker('/content-security-policy/script-src/support/worker-eval.js'); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/inside-service-worker.https.html
r246330 r279838 14 14 var sw = r.active || r.installing || r.waiting; 15 15 add_completion_callback(_ => r.unregister()); 16 16 17 17 // Forward 'securitypolicyviolation' events from the document into the 18 18 // worker (we shouldn't actually see any, so the worker will assert that -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/script-sample-no-opt-in.html
r246330 r279838 32 32 assert_equals(e.blockedURI, "inline"); 33 33 assert_equals(e.sample, ""); 34 })); 35 34 })); 35 36 36 document.body.append(a); 37 37 a.click(); … … 46 46 assert_equals(e.blockedURI, "inline"); 47 47 assert_equals(e.sample, ""); 48 })); 49 48 })); 49 50 50 document.body.append(i); 51 51 }, "JavaScript URLs in iframes should not have a sample."); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/script-sample.html
r246330 r279838 32 32 assert_equals(e.blockedURI, "inline"); 33 33 assert_equals(e.sample, "assert_unreached('inline event handler')"); 34 })); 35 34 })); 35 36 36 document.body.append(a); 37 37 a.click(); … … 46 46 assert_equals(e.blockedURI, "inline"); 47 47 assert_equals(e.sample, "javascript:'inline url'"); 48 })); 49 48 })); 49 50 50 document.body.append(i); 51 51 }, "JavaScript URLs in iframes should have a sample."); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/securitypolicyviolation-block-cross-origin-image-from-script.sub.html
r254133 r279838 21 21 assert_equals(e.statusCode, 200); 22 22 })); 23 23 24 24 var s = document.createElement("script"); 25 25 s.src = "{{location[scheme]}}://{{domains[www2]}}:{{location[port]}}/content-security-policy/support/inject-image.sub.js"; -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/securitypolicyviolation-block-cross-origin-image.sub.html
r254133 r279838 21 21 assert_equals(e.statusCode, 200); 22 22 })); 23 23 24 24 var i = document.createElement("img"); 25 25 i.src = "{{location[scheme]}}://{{hosts[alt][]}}:{{location[port]}}/content-security-policy/support/fail.png"; -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/securitypolicyviolation-block-image-from-script.sub.html
r254133 r279838 21 21 assert_equals(e.statusCode, 200); 22 22 })); 23 23 24 24 var s = document.createElement("script"); 25 25 s.src = "/content-security-policy/support/inject-image.sub.js"; -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/securitypolicyviolation-block-image.sub.html
r254133 r279838 21 21 assert_equals(e.statusCode, 200); 22 22 })); 23 23 24 24 var i = document.createElement("img"); 25 25 i.src = "/content-security-policy/support/fail.png"; -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/style-sample-no-opt-in.html
r246330 r279838 14 14 var s = document.createElement('style'); 15 15 s.innerText = "p { omg: yay !important; }"; 16 16 17 17 waitForViolation(s) 18 18 .then(t.step_func_done(e => { 19 19 assert_equals(e.blockedURI, "inline"); 20 20 assert_equals(e.sample, ""); 21 })); 21 })); 22 22 23 23 document.head.append(s); … … 28 28 p.setAttribute("style", "omg: yay !important;"); 29 29 p.innerText = "Yay!"; 30 30 31 31 waitForViolation(p) 32 32 .then(t.step_func_done(e => { 33 33 assert_equals(e.blockedURI, "inline"); 34 34 assert_equals(e.sample, ""); 35 })); 35 })); 36 36 37 37 document.head.append(p); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/style-sample.html
r246330 r279838 14 14 var s = document.createElement('style'); 15 15 s.innerText = "p { omg: yay !important; }"; 16 16 17 17 waitForViolation(s) 18 18 .then(t.step_func_done(e => { 19 19 assert_equals(e.blockedURI, "inline"); 20 20 assert_equals(e.sample, "p { omg: yay !important; }"); 21 })); 21 })); 22 22 23 23 document.head.append(s); … … 28 28 p.setAttribute("style", "omg: yay !important;"); 29 29 p.innerText = "Yay!"; 30 30 31 31 waitForViolation(p) 32 32 .then(t.step_func_done(e => { 33 33 assert_equals(e.blockedURI, "inline"); 34 34 assert_equals(e.sample, "omg: yay !important;"); 35 })); 35 })); 36 36 37 37 document.head.append(p); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/w3c-import.log
r246330 r279838 21 21 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/img-src-redirect-upgrade-reporting.https.html 22 22 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/img-src-redirect-upgrade-reporting.https.html.headers 23 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/img-src-redirect.sub.html 23 24 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/inside-dedicated-worker.html 24 25 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/inside-service-worker.https.html … … 30 31 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/securitypolicyviolation-block-image-from-script.sub.html 31 32 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/securitypolicyviolation-block-image.sub.html 33 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/source-file-blob-scheme.html 34 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/source-file-data-scheme.html 32 35 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/style-sample-no-opt-in.html 33 36 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/style-sample.html -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/injected-inline-style-allowed.sub.html
r246330 r279838 22 22 FAIL 1/2 23 23 </div> 24 24 25 25 <div id="test2"> 26 26 FAIL 2/2 27 27 </div> 28 28 29 29 <script src="support/inject-style.js"></script> 30 30 <script> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/inline-style-allowed-while-cloning-objects.sub.html
r254133 r279838 13 13 var t = async_test("Test that violation report event was fired"); 14 14 window.addEventListener("securitypolicyviolation", t.step_func_done(function(e) { 15 assert_equals(e.violatedDirective, "style-src ");15 assert_equals(e.violatedDirective, "style-src-attr"); 16 16 })); 17 17 window.onload = function() { -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/inline-style-allowed.sub.html
r246330 r279838 15 15 }); 16 16 </script> 17 17 18 18 <style> 19 19 .target { -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-allowed.sub.html
r246330 r279838 14 14 log("Fail"); 15 15 }); 16 </script> 16 </script> 17 17 <link rel="stylesheet" href="resources/blue.css"> 18 18 </head> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-blocked.sub-expected.txt
r246330 r279838 1 1 2 FAIL Expecting logs: ["violated-directive=style-src ","PASS"] assert_unreached: Logging timeout, expected logs violated-directive=style-srcnot sent. Reached unreachable code2 FAIL Expecting logs: ["violated-directive=style-src-elem","PASS"] assert_unreached: Logging timeout, expected logs violated-directive=style-src-elem not sent. Reached unreachable code 3 3 -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-blocked.sub.html
r246330 r279838 8 8 <script src="/resources/testharness.js"></script> 9 9 <script src="/resources/testharnessreport.js"></script> 10 <script src='../support/logTest.sub.js?logs=["violated-directive=style-src ","PASS"]'></script>10 <script src='../support/logTest.sub.js?logs=["violated-directive=style-src-elem","PASS"]'></script> 11 11 <script src="../support/alertAssert.sub.js?alerts=[]"></script> 12 12 <script> … … 14 14 log("violated-directive=" + e.violatedDirective); 15 15 }); 16 </script> 16 </script> 17 17 <link rel="stylesheet" href="resources/blue.css"> 18 18 </head> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-hash-allowed.html
r246330 r279838 29 29 var contentEl = document.getElementById(contentId); 30 30 var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left'); 31 assert_ true(marginLeftVal =="2px")31 assert_equals(marginLeftVal, "2px") 32 32 } 33 33 t.step(function() { -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-hash-blocked.html
r246330 r279838 30 30 var contentEl = document.getElementById(contentId); 31 31 var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left'); 32 if (assertTrue) assert_ true(marginLeftVal =="2px");33 else assert_ false(marginLeftVal =="2px");32 if (assertTrue) assert_equals(marginLeftVal, "2px"); 33 else assert_not_equals(marginLeftVal, "2px"); 34 34 } 35 35 -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-hash-default-src-allowed.html
r246330 r279838 29 29 var contentEl = document.getElementById(contentId); 30 30 var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left'); 31 assert_ true(marginLeftVal =="2px")31 assert_equals(marginLeftVal, "2px") 32 32 } 33 33 t.step(function() { -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-imported-style-allowed.sub.html
r246330 r279838 22 22 var contentEl = document.getElementById("content"); 23 23 var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left'); 24 assert_ false(marginLeftVal =="2px")24 assert_not_equals(marginLeftVal, "2px") 25 25 t.done(); 26 26 }); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-imported-style-blocked.html
r246330 r279838 30 30 var contentEl = document.getElementById("content"); 31 31 var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left'); 32 assert_ false(marginLeftVal =="2px");32 assert_not_equals(marginLeftVal, "2px"); 33 33 t.done(); 34 34 }); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-injected-inline-style-allowed.html
r246330 r279838 24 24 var contentEl = document.getElementById("content"); 25 25 var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left'); 26 assert_ true(marginLeftVal =="2px");26 assert_equals(marginLeftVal, "2px"); 27 27 var marginRightVal = getComputedStyle(contentEl).getPropertyValue('margin-right'); 28 assert_ true(marginRightVal =="2px");28 assert_equals(marginRightVal, "2px"); 29 29 }); 30 30 }); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-injected-inline-style-blocked.html
r246330 r279838 31 31 32 32 var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left'); 33 assert_ false(marginLeftVal =="2px");33 assert_not_equals(marginLeftVal, "2px"); 34 34 var marginRightVal = getComputedStyle(contentEl).getPropertyValue('margin-right'); 35 assert_ false(marginRightVal =="2px");35 assert_not_equals(marginRightVal, "2px"); 36 36 }); 37 37 </script> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-injected-stylesheet-allowed.sub-expected.txt
r246330 r279838 1 1 Blocked access to external URL http://www1.localhost:8800/content-security-policy/style-src/resources/style-src.css 2 2 3 FAIL Programatically injected stylesheet should load assert_ true: expected true got false3 FAIL Programatically injected stylesheet should load assert_equals: expected "2px" but got "0px" 4 4 Lorem ipsum -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-injected-stylesheet-allowed.sub.html
r246330 r279838 21 21 var contentEl = document.getElementById("content"); 22 22 var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left'); 23 assert_ true(marginLeftVal =="2px");23 assert_equals(marginLeftVal, "2px"); 24 24 }); 25 25 -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-injected-stylesheet-blocked.sub.html
r246330 r279838 25 25 var contentEl = document.getElementById("content"); 26 26 var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left'); 27 assert_ false(marginLeftVal =="2px");27 assert_not_equals(marginLeftVal, "2px"); 28 28 }); 29 29 -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-inline-style-allowed.html
r246330 r279838 26 26 var contentEl = document.getElementById("content"); 27 27 var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left'); 28 assert_ true(marginLeftVal =="2px");28 assert_equals(marginLeftVal, "2px"); 29 29 t.done(); 30 30 }, "Inline style should not be applied"); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-inline-style-attribute-allowed.html
r246330 r279838 12 12 var contentEl = document.getElementById("content"); 13 13 var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left'); 14 assert_ true(marginLeftVal =="2px");14 assert_equals(marginLeftVal, "2px"); 15 15 }); 16 16 </script> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-inline-style-attribute-blocked.html
r246330 r279838 16 16 var contentEl = document.getElementById("content"); 17 17 var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left'); 18 assert_ false(marginLeftVal =="2px");18 assert_not_equals(marginLeftVal, "2px"); 19 19 }); 20 20 </script> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-inline-style-blocked.html
r246330 r279838 30 30 var contentEl = document.getElementById("content"); 31 31 var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left'); 32 assert_ false(marginLeftVal =="2px");32 assert_not_equals(marginLeftVal, "2px"); 33 33 t.done(); 34 34 }); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-inline-style-nonce-allowed.html
r246330 r279838 26 26 var contentEl = document.getElementById("content"); 27 27 var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left'); 28 assert_ true(marginLeftVal =="2px");28 assert_equals(marginLeftVal, "2px"); 29 29 t.done(); 30 30 }); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-inline-style-nonce-blocked-error-event.html
r246330 r279838 28 28 function verifyStep1() { 29 29 var marginLeft = getComputedStyle(document.querySelector("#content")).getPropertyValue('margin-left'); 30 assert_ false(marginLeft =='2px', "Content still does not have a 2px margin-left after initial style.");30 assert_not_equals(marginLeft, '2px', "Content still does not have a 2px margin-left after initial style."); 31 31 } 32 32 … … 40 40 function verifyStep2() { 41 41 var marginLeft = getComputedStyle(document.querySelector("#content")).getPropertyValue('margin-left'); 42 assert_ false(marginLeft =='2px', "Content still does not have a 2px margin-left after inserted style.");42 assert_not_equals(marginLeft, '2px', "Content still does not have a 2px margin-left after inserted style."); 43 43 } 44 44 … … 49 49 function verifyStep3() { 50 50 var marginLeft = getComputedStyle(document.querySelector("#content")).getPropertyValue('margin-left'); 51 assert_ false(marginLeft =='2px', "Content still does not have a 2px margin-left after changing style.");51 assert_not_equals(marginLeft, '2px', "Content still does not have a 2px margin-left after changing style."); 52 52 test.done(); 53 53 } -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-inline-style-nonce-blocked.html
r246330 r279838 29 29 var contentEl = document.getElementById("content"); 30 30 var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left'); 31 assert_ false(marginLeftVal =="2px");31 assert_not_equals(marginLeftVal, "2px"); 32 32 t.done(); 33 33 }); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-multiple-policies-multiple-hashing-algorithms.html.sub.headers
r246330 r279838 4 4 Pragma: no-cache 5 5 Set-Cookie: style-src-multiple-policies-multiple-hashing-algorithms={{$id:uuid()}}; Path=/content-security-policy/style-src/ 6 Content-Security-Policy: style-src 'sha256-rB6kiow2O3eFUeTNyyLeK3wV0+l7vNB90J1aqllKvjg='; script-src 'unsafe-inline' 'self'; report-uri ../support/report.py?op=put&reportID={{$id}}7 Content-Security-Policy: style-src 'sha384-DAShdG5sejEaOdWfT+TQMRP5mHssKiUNjFggNnElIvIoj048XQlacVRs+za2AM1a'; script-src 'unsafe-inline' 'self'; report-uri ../support/report.py?op=put&reportID={{$id}}6 Content-Security-Policy: style-src 'sha256-rB6kiow2O3eFUeTNyyLeK3wV0+l7vNB90J1aqllKvjg='; script-src 'unsafe-inline' 'self'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} 7 Content-Security-Policy: style-src 'sha384-DAShdG5sejEaOdWfT+TQMRP5mHssKiUNjFggNnElIvIoj048XQlacVRs+za2AM1a'; script-src 'unsafe-inline' 'self'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-none-blocked.html
r246330 r279838 25 25 var contentEl = document.getElementById("content"); 26 26 var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left'); 27 assert_ false(marginLeftVal =="2px");27 assert_not_equals(marginLeftVal, "2px"); 28 28 t.done(); 29 29 }); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-star-allowed.html
r246330 r279838 22 22 var contentEl = document.getElementById("content"); 23 23 var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left'); 24 assert_ true(marginLeftVal =="2px");24 assert_equals(marginLeftVal, "2px"); 25 25 t.done(); 26 26 }); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-stylesheet-nonce-allowed.html
r254133 r279838 22 22 var contentEl = document.getElementById("content"); 23 23 var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left'); 24 assert_ true(marginLeftVal =="2px");24 assert_equals(marginLeftVal, "2px"); 25 25 t.done(); 26 26 }); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-stylesheet-nonce-blocked.html
r254133 r279838 25 25 var contentEl = document.getElementById("content"); 26 26 var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left'); 27 assert_ false(marginLeftVal =="2px");27 assert_not_equals(marginLeftVal, "2px"); 28 28 t.done(); 29 29 }); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/stylehash-allowed.sub.html
r246330 r279838 13 13 alert_assert("Fail"); 14 14 }); 15 15 16 16 var t_alert = async_test('Expecting alerts: ["PASS (1/4): The \'#p1\' element\'s text is green, which means the style was correctly applied.","PASS (2/4): The \'#p2\' element\'s text is green, which means the style was correctly applied.","PASS (3/4): The \'#p3\' element\'s text is green, which means the style was correctly applied.","PASS (4/4): The \'#p4\' element\'s text is green, which means the style was correctly applied."]'); 17 17 var expected_alerts = ["PASS (1/4): The '#p1' element's text is green, which means the style was correctly applied.", "PASS (2/4): The '#p2' element's text is green, which means the style was correctly applied.", "PASS (3/4): The '#p3' element's text is green, which means the style was correctly applied.", "PASS (4/4): The '#p4' element's text is green, which means the style was correctly applied."]; … … 25 25 for (var i = 0; i < expected_alerts.length; i++) { 26 26 if (expected_alerts[i] == msg) { 27 assert_ true(expected_alerts[i] ==msg);27 assert_equals(expected_alerts[i], msg); 28 28 expected_alerts.splice(i, 1); 29 29 if (expected_alerts.length == 0) { -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/stylehash-basic-blocked.sub.html
r246330 r279838 25 25 for (var i = 0; i < expected_alerts.length; i++) { 26 26 if (expected_alerts[i] == msg) { 27 assert_ true(expected_alerts[i] ==msg);27 assert_equals(expected_alerts[i], msg); 28 28 expected_alerts.splice(i, 1); 29 29 if (expected_alerts.length == 0) { -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/w3c-import.log
r246330 r279838 28 28 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-hash-allowed.html 29 29 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-hash-blocked.html 30 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-hash-case-insensitive.html 30 31 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-hash-default-src-allowed.html 31 32 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-imported-style-allowed.sub.html -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/support/alertAssert.sub.js
r246330 r279838 29 29 for (var i = 0; i < expected_alerts.length; i++) { 30 30 if (expected_alerts[i] == msg) { 31 assert_ true(expected_alerts[i] ==msg);31 assert_equals(expected_alerts[i], msg); 32 32 expected_alerts.splice(i, 1); 33 33 if (expected_alerts.length == 0) { -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/support/checkReport.sub.js
r279169 r279838 49 49 // not exceed the test timeouts set by vendors otherwise the test would fail. 50 50 var timeout = document.querySelector("meta[name=timeout][content=long]") ? 20 : 3; 51 var reportLocation = location.protocol + "//" + location.host + "/ content-security-policy/support/report.py?op=retrieve_report&timeout=" + timeout + "&reportID=" + reportID;51 var reportLocation = location.protocol + "//" + location.host + "/reporting/resources/report.py?op=retrieve_report&timeout=" + timeout + "&reportID=" + reportID; 52 52 53 53 if (testName == "") testName = "Violation report status OK."; … … 116 116 cookieTest.done(); 117 117 }); 118 var cReportLocation = location.protocol + "//" + location.host + "/ content-security-policy/support/report.py?op=retrieve_cookies&timeout=" + timeout + "&reportID=" + reportID;118 var cReportLocation = location.protocol + "//" + location.host + "/reporting/resources/report.py?op=retrieve_cookies&timeout=" + timeout + "&reportID=" + reportID; 119 119 cookieReport.open("GET", cReportLocation, true); 120 120 cookieReport.send(); … … 131 131 reportCountTest.done(); 132 132 }); 133 var cReportLocation = location.protocol + "//" + location.host + "/ content-security-policy/support/report.py?op=retrieve_count&timeout=" + timeout + "&reportID=" + reportID;133 var cReportLocation = location.protocol + "//" + location.host + "/reporting/resources/report.py?op=retrieve_count&timeout=" + timeout + "&reportID=" + reportID; 134 134 reportCountReport.open("GET", cReportLocation, true); 135 135 reportCountReport.send(); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/support/echo-policy.py
r246330 r279838 1 1 def main(request, response): 2 policy = request.GET.first( "policy");3 return [( "Content-Type", "text/html"), ("Content-Security-Policy", policy)],"<!DOCTYPE html><title>Echo.</title>"2 policy = request.GET.first(b"policy") 3 return [(b"Content-Type", b"text/html"), (b"Content-Security-Policy", policy)], b"<!DOCTYPE html><title>Echo.</title>" -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/support/logTest.sub.js
r246330 r279838 27 27 for (var i = 0; i < expected_logs.length; i++) { 28 28 if (expected_logs[i] == msg) { 29 assert_ true(expected_logs[i] ==msg);29 assert_equals(expected_logs[i], msg); 30 30 expected_logs.splice(i, 1); 31 31 if (expected_logs.length == 0) { -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/support/prefetch-helper.js
r246330 r279838 1 test(t => { 2 assert_true(document.createElement('link').relList.supports('prefetch')); 3 }, "Browser supports prefetch."); 4 5 test(t => { 6 assert_true(!!window.PerformanceResourceTiming); 7 }, "Browser supports performance APIs."); 1 setup(_ => { 2 assert_implements_optional( 3 document.createElement('link').relList.supports('prefetch'), 4 "Browser supports prefetch."); 5 assert_implements_optional( 6 "PerformanceResourceTiming" in window, 7 "Browser supports performance APIs."); 8 }); 8 9 9 10 async function waitUntilResourceDownloaded(url) { -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/support/resource.py
r246330 r279838 1 1 def main(request, response): 2 2 headers = [] 3 headers.append(( "Access-Control-Allow-Origin","*"))3 headers.append((b"Access-Control-Allow-Origin", b"*")) 4 4 5 return headers, "{ \"result\": \"success\" }"5 return headers, b"{ \"result\": \"success\" }" -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/support/testharness-helper.js
r263605 r279838 41 41 // function builds a test that asserts that the ping is received, 42 42 // and that no CSP event fires. 43 function assert_worker_is_loaded(url, description ) {43 function assert_worker_is_loaded(url, description, expected_message = "ping") { 44 44 async_test(t => { 45 45 assert_no_csp_event_for_url(t, url); … … 48 48 waitUntilEvent(w, "message") 49 49 .then(t.step_func_done(e => { 50 assert_equals(e.data, "ping");50 assert_equals(e.data, expected_message); 51 51 })); 52 52 }, description); 53 53 } 54 54 55 function assert_shared_worker_is_loaded(url, description ) {55 function assert_shared_worker_is_loaded(url, description, expected_message = "ping") { 56 56 async_test(t => { 57 57 assert_no_csp_event_for_url(t, url); … … 60 60 waitUntilEvent(w.port, "message") 61 61 .then(t.step_func_done(e => { 62 assert_equals(e.data, "ping");62 assert_equals(e.data, expected_message); 63 63 })); 64 64 w.port.start(); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/support/w3c-import.log
r246330 r279838 43 43 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/support/prefetch-subresource.css 44 44 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/support/prefetch-subresource.css.headers 45 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/support/report.py46 45 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/support/resource.py 47 46 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/support/service-worker-helper.js -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/eval-blocked-in-about-blank-iframe.sub.html
r246330 r279838 20 20 }); 21 21 window.onmessage = function(e) { 22 log(e.data); 22 log(e.data); 23 23 } 24 24 window.onload = function() { -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/eval-scripts-setInterval-allowed.sub.html
r246330 r279838 16 16 log("Fail"); 17 17 }); 18 18 19 19 var id_string = setInterval("clearInterval(id_string); log('PASS 1 of 2')", 0); 20 20 if (id_string == 0) 21 21 log('FAIL: Return value for string (should not be 0): ' + id_string); 22 22 23 23 var id_function = setInterval(function() { 24 24 clearInterval(id_function); 25 25 log('PASS 2 of 2'); 26 26 }, 0); 27 27 28 28 if (id_function == 0) 29 29 log('FAIL'); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/eval-scripts-setInterval-blocked.sub.html
r246330 r279838 15 15 log("violated-directive=" + e.violatedDirective); 16 16 }); 17 17 18 18 var id = setInterval("alert_assert('FAIL')", 0); 19 19 if (id != 0) 20 20 log('FAIL: Return value for string (should be 0): ' + id); 21 21 22 22 var id = setInterval(function() { 23 23 clearInterval(id); 24 24 log('PASS'); 25 25 }, 0); 26 26 27 27 if (id == 0) 28 28 log('FAIL'); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/eval-scripts-setTimeout-allowed.sub.html
r246330 r279838 15 15 log("Fail"); 16 16 }); 17 17 18 18 var id = setTimeout("log('PASS 1 of 2')", 0); 19 19 if (id == 0) -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/eval-scripts-setTimeout-blocked.sub.html
r246330 r279838 15 15 log("violated-directive=" + e.violatedDirective); 16 16 }); 17 17 18 18 var id = setTimeout("alert_assert('FAIL')", 0); 19 19 if (id != 0) 20 20 log('FAIL'); 21 21 22 22 var id = setTimeout(function() { 23 23 log('PASS'); 24 24 }, 0); 25 25 26 26 if (id == 0) 27 27 log('FAIL'); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/function-constructor-blocked.sub.html
r246330 r279838 17 17 log("violated-directive=" + e.violatedDirective); 18 18 }); 19 19 20 20 try { 21 21 (new Function("log('FAIL')"))(); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/w3c-import.log
r246330 r279838 19 19 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/eval-blocked-in-about-blank-iframe.sub.html 20 20 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/eval-blocked.sub.html 21 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/eval-in-iframe.html 21 22 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/eval-scripts-setInterval-allowed.sub.html 22 23 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/eval-scripts-setInterval-blocked.sub.html -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-hashes/javascript_src_allowed-href_blank.html
r246330 r279838 14 14 <body> 15 15 <div id='log'></div> 16 <a target="_blank" href='javascript:opener.t1.done();' id='test'>16 <a target="_blank" rel="opener" href='javascript:opener.t1.done();' id='test'> 17 17 <script nonce='abc'> 18 18 var t1 = async_test("Test that the javascript: src is allowed to run"); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-hashes/javascript_src_allowed-window_location.html
r246330 r279838 19 19 }); 20 20 21 window.open('support/child_window_location_navigate.sub.html' + 21 window.open('support/child_window_location_navigate.sub.html' + 22 22 '?csp=' + encodeURI("script-src 'unsafe-hashes' 'nonce-abc' 'sha256-IIiAJ8UuliU8o1qAv6CV4P3R8DeTf/v3MrsCwXW171Y='") + 23 23 '&url=' + encodeURI("javascript:opener.postMessage('pass', '*')")); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-hashes/javascript_src_denied_missing_unsafe_hashes-window_location.html
r246330 r279838 19 19 }); 20 20 21 window.open('support/child_window_location_navigate.sub.html' + 21 window.open('support/child_window_location_navigate.sub.html' + 22 22 '?csp=' + encodeURI("script-src 'nonce-abc' 'sha256-IIiAJ8UuliU8o1qAv6CV4P3R8DeTf/v3MrsCwXW171Y='") + 23 23 '&url=' + encodeURI("javascript:opener.postMessage('pass', '*')")); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-hashes/javascript_src_denied_wrong_hash-window_location.html
r246330 r279838 19 19 }); 20 20 21 window.open('support/child_window_location_navigate.sub.html' + 21 window.open('support/child_window_location_navigate.sub.html' + 22 22 '?csp=' + encodeURI("script-src 'unsafe-hashes' 'nonce-abc' 'sha256-VjH6k67F4kobUnNDOBE85QiJ9cuZMiYT6desKXvezVg='") + 23 23 '&url=' + encodeURI("javascript:opener.postMessage('pass', '*')")); -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-hashes/script_event_handlers_allowed.html
r246330 r279838 13 13 <script nonce='abc'> 14 14 var t1 = async_test("Test that the inline event handler is allowed to run"); 15 15 16 16 window.addEventListener('securitypolicyviolation', t1.unreached_func("Should have not raised any event")); 17 17 </script> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-hashes/support/child_window_location_navigate.sub.html
r246330 r279838 7 7 8 8 <body> 9 10 <span id="escape">{{GET[url]}}</span> 11 9 12 <script nonce='abc'> 10 13 window.addEventListener('securitypolicyviolation', function(e) { … … 12 15 }); 13 16 14 window.location.href = "{{GET[url]}}";17 window.location.href = document.getElementById("escape").textContent; 15 18 </script> 16 19 </body> -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/w3c-import.log
r246330 r279838 18 18 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/README.css 19 19 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/README.html 20 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/spec.src.json -
trunk/LayoutTests/platform/mac-wk1/TestExpectations
r279725 r279838 345 345 http/wpt/cache-storage [ Skip ] 346 346 http/wpt/service-workers [ Skip ] 347 imported/w3c/web-platform-tests/content-security-policy/inside-worker/serviceworker-report-only.https.sub.html [ Skip ] 348 imported/w3c/web-platform-tests/content-security-policy/sandbox/service-worker-sandbox.https.html [ Skip ] 347 349 imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/inside-service-worker.https.html [ Skip ] 348 350 imported/w3c/web-platform-tests/content-security-policy/worker-src/service-child.https.sub.html [ Skip ] -
trunk/LayoutTests/platform/mac-wk1/imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-same-none-block-expected.txt
r262312 r279838 1 Blocked access to external URL http://www1.localhost:8801/content-security-policy/frame-ancestors/support/frame-ancestors.sub.html?policy= 'none&%23x27;1 Blocked access to external URL http://www1.localhost:8801/content-security-policy/frame-ancestors/support/frame-ancestors.sub.html?policy=%27none%27 2 2 3 3 -
trunk/LayoutTests/platform/mac-wk1/imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-same-self-block-expected.txt
r262312 r279838 1 Blocked access to external URL http://www1.localhost:8801/content-security-policy/frame-ancestors/support/frame-ancestors.sub.html?policy= 'self&%23x27;1 Blocked access to external URL http://www1.localhost:8801/content-security-policy/frame-ancestors/support/frame-ancestors.sub.html?policy=%27self%27 2 2 3 3 -
trunk/LayoutTests/tests-options.json
r279585 r279838 567 567 "slow" 568 568 ], 569 "imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/required_csp-header-crlf.html": [ 570 "slow" 571 ], 569 572 "imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/required_csp-header.html": [ 570 573 "slow" 571 574 ], 575 "imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-same-star-allow.html": [ 576 "slow" 577 ], 572 578 "imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/report-blocked-frame.sub.html": [ 573 579 "slow" 574 580 ], 575 581 "imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/report-only-frame.sub.html": [ 582 "slow" 583 ], 584 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/script-tag.http.html": [ 585 "slow" 586 ], 587 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/script-tag.https.html": [ 588 "slow" 589 ], 590 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-classic.http.html": [ 591 "slow" 592 ], 593 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-classic.https.html": [ 594 "slow" 595 ], 596 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-import-data.http.html": [ 597 "slow" 598 ], 599 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-import-data.https.html": [ 600 "slow" 601 ], 602 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-import.http.html": [ 603 "slow" 604 ], 605 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-import.https.html": [ 606 "slow" 607 ], 608 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-module.http.html": [ 609 "slow" 610 ], 611 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-module.https.html": [ 612 "slow" 613 ], 614 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-classic.http.html": [ 615 "slow" 616 ], 617 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-classic.https.html": [ 618 "slow" 619 ], 620 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-import-data.http.html": [ 621 "slow" 622 ], 623 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-import-data.https.html": [ 624 "slow" 625 ], 626 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-import.http.html": [ 627 "slow" 628 ], 629 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-import.https.html": [ 630 "slow" 631 ], 632 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-module.http.html": [ 633 "slow" 634 ], 635 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-module.https.html": [ 636 "slow" 637 ], 638 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-animation-import-data.https.html": [ 639 "slow" 640 ], 641 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-animation.https.html": [ 642 "slow" 643 ], 644 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-audio-import-data.https.html": [ 645 "slow" 646 ], 647 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-audio.https.html": [ 648 "slow" 649 ], 650 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-layout-import-data.https.html": [ 651 "slow" 652 ], 653 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-layout.https.html": [ 654 "slow" 655 ], 656 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-paint-import-data.https.html": [ 657 "slow" 658 ], 659 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-paint.https.html": [ 660 "slow" 661 ], 662 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/script-tag.http.html": [ 663 "slow" 664 ], 665 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/script-tag.https.html": [ 666 "slow" 667 ], 668 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-classic.http.html": [ 669 "slow" 670 ], 671 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-classic.https.html": [ 672 "slow" 673 ], 674 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-import-data.http.html": [ 675 "slow" 676 ], 677 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-import-data.https.html": [ 678 "slow" 679 ], 680 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-import.http.html": [ 681 "slow" 682 ], 683 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-import.https.html": [ 684 "slow" 685 ], 686 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-module.http.html": [ 687 "slow" 688 ], 689 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-module.https.html": [ 690 "slow" 691 ], 692 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-classic.http.html": [ 693 "slow" 694 ], 695 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-classic.https.html": [ 696 "slow" 697 ], 698 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-import-data.http.html": [ 699 "slow" 700 ], 701 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-import-data.https.html": [ 702 "slow" 703 ], 704 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-import.http.html": [ 705 "slow" 706 ], 707 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-import.https.html": [ 708 "slow" 709 ], 710 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-module.http.html": [ 711 "slow" 712 ], 713 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-module.https.html": [ 714 "slow" 715 ], 716 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-animation-import-data.https.html": [ 717 "slow" 718 ], 719 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-animation.https.html": [ 720 "slow" 721 ], 722 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-audio-import-data.https.html": [ 723 "slow" 724 ], 725 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-audio.https.html": [ 726 "slow" 727 ], 728 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-layout-import-data.https.html": [ 729 "slow" 730 ], 731 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-layout.https.html": [ 732 "slow" 733 ], 734 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-paint-import-data.https.html": [ 735 "slow" 736 ], 737 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-paint.https.html": [ 738 "slow" 739 ], 740 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/script-tag.http.html": [ 741 "slow" 742 ], 743 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/script-tag.https.html": [ 744 "slow" 745 ], 746 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-classic.http.html": [ 747 "slow" 748 ], 749 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-classic.https.html": [ 750 "slow" 751 ], 752 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-import-data.http.html": [ 753 "slow" 754 ], 755 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-import-data.https.html": [ 756 "slow" 757 ], 758 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-import.http.html": [ 759 "slow" 760 ], 761 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-import.https.html": [ 762 "slow" 763 ], 764 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-module.http.html": [ 765 "slow" 766 ], 767 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-module.https.html": [ 768 "slow" 769 ], 770 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-classic.http.html": [ 771 "slow" 772 ], 773 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-classic.https.html": [ 774 "slow" 775 ], 776 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-import-data.http.html": [ 777 "slow" 778 ], 779 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-import-data.https.html": [ 780 "slow" 781 ], 782 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-import.http.html": [ 783 "slow" 784 ], 785 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-import.https.html": [ 786 "slow" 787 ], 788 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-module.http.html": [ 789 "slow" 790 ], 791 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-module.https.html": [ 792 "slow" 793 ], 794 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-animation-import-data.https.html": [ 795 "slow" 796 ], 797 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-animation.https.html": [ 798 "slow" 799 ], 800 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-audio-import-data.https.html": [ 801 "slow" 802 ], 803 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-audio.https.html": [ 804 "slow" 805 ], 806 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-layout-import-data.https.html": [ 807 "slow" 808 ], 809 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-layout.https.html": [ 810 "slow" 811 ], 812 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-paint-import-data.https.html": [ 813 "slow" 814 ], 815 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-paint.https.html": [ 816 "slow" 817 ], 818 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/script-tag.http.html": [ 819 "slow" 820 ], 821 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/script-tag.https.html": [ 822 "slow" 823 ], 824 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-classic.http.html": [ 825 "slow" 826 ], 827 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-classic.https.html": [ 828 "slow" 829 ], 830 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-import-data.http.html": [ 831 "slow" 832 ], 833 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-import-data.https.html": [ 834 "slow" 835 ], 836 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-import.http.html": [ 837 "slow" 838 ], 839 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-import.https.html": [ 840 "slow" 841 ], 842 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-module.http.html": [ 843 "slow" 844 ], 845 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-module.https.html": [ 846 "slow" 847 ], 848 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-classic.http.html": [ 849 "slow" 850 ], 851 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-classic.https.html": [ 852 "slow" 853 ], 854 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-import-data.http.html": [ 855 "slow" 856 ], 857 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-import-data.https.html": [ 858 "slow" 859 ], 860 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-import.http.html": [ 861 "slow" 862 ], 863 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-import.https.html": [ 864 "slow" 865 ], 866 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-module.http.html": [ 867 "slow" 868 ], 869 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-module.https.html": [ 870 "slow" 871 ], 872 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-animation-import-data.https.html": [ 873 "slow" 874 ], 875 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-animation.https.html": [ 876 "slow" 877 ], 878 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-audio-import-data.https.html": [ 879 "slow" 880 ], 881 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-audio.https.html": [ 882 "slow" 883 ], 884 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-layout-import-data.https.html": [ 885 "slow" 886 ], 887 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-layout.https.html": [ 888 "slow" 889 ], 890 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-paint-import-data.https.html": [ 891 "slow" 892 ], 893 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-paint.https.html": [ 894 "slow" 895 ], 896 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/script-tag.http.html": [ 897 "slow" 898 ], 899 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/script-tag.https.html": [ 900 "slow" 901 ], 902 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-classic.http.html": [ 903 "slow" 904 ], 905 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-classic.https.html": [ 906 "slow" 907 ], 908 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-import-data.http.html": [ 909 "slow" 910 ], 911 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-import-data.https.html": [ 912 "slow" 913 ], 914 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-import.http.html": [ 915 "slow" 916 ], 917 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-import.https.html": [ 918 "slow" 919 ], 920 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-module.http.html": [ 921 "slow" 922 ], 923 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-module.https.html": [ 924 "slow" 925 ], 926 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-classic.http.html": [ 927 "slow" 928 ], 929 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-classic.https.html": [ 930 "slow" 931 ], 932 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-import-data.http.html": [ 933 "slow" 934 ], 935 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-import-data.https.html": [ 936 "slow" 937 ], 938 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-import.http.html": [ 939 "slow" 940 ], 941 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-import.https.html": [ 942 "slow" 943 ], 944 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-module.http.html": [ 945 "slow" 946 ], 947 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-module.https.html": [ 948 "slow" 949 ], 950 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-animation-import-data.https.html": [ 951 "slow" 952 ], 953 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-animation.https.html": [ 954 "slow" 955 ], 956 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-audio-import-data.https.html": [ 957 "slow" 958 ], 959 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-audio.https.html": [ 960 "slow" 961 ], 962 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-layout-import-data.https.html": [ 963 "slow" 964 ], 965 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-layout.https.html": [ 966 "slow" 967 ], 968 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-paint-import-data.https.html": [ 969 "slow" 970 ], 971 "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-paint.https.html": [ 972 "slow" 973 ], 974 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/script-tag.http.html": [ 975 "slow" 976 ], 977 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/script-tag.https.html": [ 978 "slow" 979 ], 980 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-classic.http.html": [ 981 "slow" 982 ], 983 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-classic.https.html": [ 984 "slow" 985 ], 986 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-import-data.http.html": [ 987 "slow" 988 ], 989 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-import-data.https.html": [ 990 "slow" 991 ], 992 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-import.http.html": [ 993 "slow" 994 ], 995 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-import.https.html": [ 996 "slow" 997 ], 998 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-module.http.html": [ 999 "slow" 1000 ], 1001 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-module.https.html": [ 1002 "slow" 1003 ], 1004 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-classic.http.html": [ 1005 "slow" 1006 ], 1007 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-classic.https.html": [ 1008 "slow" 1009 ], 1010 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-import-data.http.html": [ 1011 "slow" 1012 ], 1013 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-import-data.https.html": [ 1014 "slow" 1015 ], 1016 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-import.http.html": [ 1017 "slow" 1018 ], 1019 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-import.https.html": [ 1020 "slow" 1021 ], 1022 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-module.http.html": [ 1023 "slow" 1024 ], 1025 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-module.https.html": [ 1026 "slow" 1027 ], 1028 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-animation-import-data.https.html": [ 1029 "slow" 1030 ], 1031 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-animation.https.html": [ 1032 "slow" 1033 ], 1034 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-audio-import-data.https.html": [ 1035 "slow" 1036 ], 1037 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-audio.https.html": [ 1038 "slow" 1039 ], 1040 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-layout-import-data.https.html": [ 1041 "slow" 1042 ], 1043 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-layout.https.html": [ 1044 "slow" 1045 ], 1046 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-paint-import-data.https.html": [ 1047 "slow" 1048 ], 1049 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-paint.https.html": [ 1050 "slow" 1051 ], 1052 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/script-tag.http.html": [ 1053 "slow" 1054 ], 1055 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/script-tag.https.html": [ 1056 "slow" 1057 ], 1058 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-classic.http.html": [ 1059 "slow" 1060 ], 1061 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-classic.https.html": [ 1062 "slow" 1063 ], 1064 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-import-data.http.html": [ 1065 "slow" 1066 ], 1067 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-import-data.https.html": [ 1068 "slow" 1069 ], 1070 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-import.http.html": [ 1071 "slow" 1072 ], 1073 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-import.https.html": [ 1074 "slow" 1075 ], 1076 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-module.http.html": [ 1077 "slow" 1078 ], 1079 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-module.https.html": [ 1080 "slow" 1081 ], 1082 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-classic.http.html": [ 1083 "slow" 1084 ], 1085 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-classic.https.html": [ 1086 "slow" 1087 ], 1088 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-import-data.http.html": [ 1089 "slow" 1090 ], 1091 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-import-data.https.html": [ 1092 "slow" 1093 ], 1094 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-import.http.html": [ 1095 "slow" 1096 ], 1097 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-import.https.html": [ 1098 "slow" 1099 ], 1100 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-module.http.html": [ 1101 "slow" 1102 ], 1103 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-module.https.html": [ 1104 "slow" 1105 ], 1106 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-animation-import-data.https.html": [ 1107 "slow" 1108 ], 1109 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-animation.https.html": [ 1110 "slow" 1111 ], 1112 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-audio-import-data.https.html": [ 1113 "slow" 1114 ], 1115 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-audio.https.html": [ 1116 "slow" 1117 ], 1118 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-layout-import-data.https.html": [ 1119 "slow" 1120 ], 1121 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-layout.https.html": [ 1122 "slow" 1123 ], 1124 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-paint-import-data.https.html": [ 1125 "slow" 1126 ], 1127 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-paint.https.html": [ 1128 "slow" 1129 ], 1130 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/script-tag.http.html": [ 1131 "slow" 1132 ], 1133 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/script-tag.https.html": [ 1134 "slow" 1135 ], 1136 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-classic.http.html": [ 1137 "slow" 1138 ], 1139 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-classic.https.html": [ 1140 "slow" 1141 ], 1142 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-import-data.http.html": [ 1143 "slow" 1144 ], 1145 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-import-data.https.html": [ 1146 "slow" 1147 ], 1148 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-import.http.html": [ 1149 "slow" 1150 ], 1151 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-import.https.html": [ 1152 "slow" 1153 ], 1154 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-module.http.html": [ 1155 "slow" 1156 ], 1157 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-module.https.html": [ 1158 "slow" 1159 ], 1160 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-classic.http.html": [ 1161 "slow" 1162 ], 1163 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-classic.https.html": [ 1164 "slow" 1165 ], 1166 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-import-data.http.html": [ 1167 "slow" 1168 ], 1169 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-import-data.https.html": [ 1170 "slow" 1171 ], 1172 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-import.http.html": [ 1173 "slow" 1174 ], 1175 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-import.https.html": [ 1176 "slow" 1177 ], 1178 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-module.http.html": [ 1179 "slow" 1180 ], 1181 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-module.https.html": [ 1182 "slow" 1183 ], 1184 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-animation-import-data.https.html": [ 1185 "slow" 1186 ], 1187 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-animation.https.html": [ 1188 "slow" 1189 ], 1190 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-audio-import-data.https.html": [ 1191 "slow" 1192 ], 1193 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-audio.https.html": [ 1194 "slow" 1195 ], 1196 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-layout-import-data.https.html": [ 1197 "slow" 1198 ], 1199 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-layout.https.html": [ 1200 "slow" 1201 ], 1202 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-paint-import-data.https.html": [ 1203 "slow" 1204 ], 1205 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-paint.https.html": [ 1206 "slow" 1207 ], 1208 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/script-tag.http.html": [ 1209 "slow" 1210 ], 1211 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/script-tag.https.html": [ 1212 "slow" 1213 ], 1214 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-classic.http.html": [ 1215 "slow" 1216 ], 1217 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-classic.https.html": [ 1218 "slow" 1219 ], 1220 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-import-data.http.html": [ 1221 "slow" 1222 ], 1223 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-import-data.https.html": [ 1224 "slow" 1225 ], 1226 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-import.http.html": [ 1227 "slow" 1228 ], 1229 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-import.https.html": [ 1230 "slow" 1231 ], 1232 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-module.http.html": [ 1233 "slow" 1234 ], 1235 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-module.https.html": [ 1236 "slow" 1237 ], 1238 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-classic.http.html": [ 1239 "slow" 1240 ], 1241 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-classic.https.html": [ 1242 "slow" 1243 ], 1244 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-import-data.http.html": [ 1245 "slow" 1246 ], 1247 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-import-data.https.html": [ 1248 "slow" 1249 ], 1250 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-import.http.html": [ 1251 "slow" 1252 ], 1253 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-import.https.html": [ 1254 "slow" 1255 ], 1256 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-module.http.html": [ 1257 "slow" 1258 ], 1259 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-module.https.html": [ 1260 "slow" 1261 ], 1262 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-animation-import-data.https.html": [ 1263 "slow" 1264 ], 1265 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-animation.https.html": [ 1266 "slow" 1267 ], 1268 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-audio-import-data.https.html": [ 1269 "slow" 1270 ], 1271 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-audio.https.html": [ 1272 "slow" 1273 ], 1274 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-layout-import-data.https.html": [ 1275 "slow" 1276 ], 1277 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-layout.https.html": [ 1278 "slow" 1279 ], 1280 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-paint-import-data.https.html": [ 1281 "slow" 1282 ], 1283 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-paint.https.html": [ 1284 "slow" 1285 ], 1286 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/script-tag.http.html": [ 1287 "slow" 1288 ], 1289 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/script-tag.https.html": [ 1290 "slow" 1291 ], 1292 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-classic.http.html": [ 1293 "slow" 1294 ], 1295 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-classic.https.html": [ 1296 "slow" 1297 ], 1298 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-import-data.http.html": [ 1299 "slow" 1300 ], 1301 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-import-data.https.html": [ 1302 "slow" 1303 ], 1304 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-import.http.html": [ 1305 "slow" 1306 ], 1307 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-import.https.html": [ 1308 "slow" 1309 ], 1310 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-module.http.html": [ 1311 "slow" 1312 ], 1313 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-module.https.html": [ 1314 "slow" 1315 ], 1316 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-classic.http.html": [ 1317 "slow" 1318 ], 1319 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-classic.https.html": [ 1320 "slow" 1321 ], 1322 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-import-data.http.html": [ 1323 "slow" 1324 ], 1325 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-import-data.https.html": [ 1326 "slow" 1327 ], 1328 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-import.http.html": [ 1329 "slow" 1330 ], 1331 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-import.https.html": [ 1332 "slow" 1333 ], 1334 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-module.http.html": [ 1335 "slow" 1336 ], 1337 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-module.https.html": [ 1338 "slow" 1339 ], 1340 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-animation-import-data.https.html": [ 1341 "slow" 1342 ], 1343 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-animation.https.html": [ 1344 "slow" 1345 ], 1346 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-audio-import-data.https.html": [ 1347 "slow" 1348 ], 1349 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-audio.https.html": [ 1350 "slow" 1351 ], 1352 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-layout-import-data.https.html": [ 1353 "slow" 1354 ], 1355 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-layout.https.html": [ 1356 "slow" 1357 ], 1358 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-paint-import-data.https.html": [ 1359 "slow" 1360 ], 1361 "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-paint.https.html": [ 576 1362 "slow" 577 1363 ],
Note:
See TracChangeset
for help on using the changeset viewer.