⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 279838 in webkit


Ignore:
Timestamp:
Jul 12, 2021, 10:59:36 AM (5 years ago)
Author:
Chris Dumez
Message:

Resync content-security-policy web-platform-tests from upstream
https://bugs.webkit.org/show_bug.cgi?id=227651

Reviewed by Sam Weinig.

LayoutTests/imported/w3c:

Resync content-security-policy web-platform-tests from upstream 2c19d6ee62676ac90146.

  • resources/import-expectations.json:
  • resources/resource-files.json:
  • web-platform-tests/content-security-policy/*: Updated.
  • web-platform-tests/reporting/*: Imported.

LayoutTests:

Location:
trunk/LayoutTests
Files:
816 added
27 deleted
269 edited
1 copied
8 moved

Legend:

Unmodified
Added
Removed
  • trunk/LayoutTests/ChangeLog

    r279831 r279838  
     12021-07-12  Chris Dumez  <cdumez@apple.com>
     2
     3        Resync content-security-policy web-platform-tests from upstream
     4        https://bugs.webkit.org/show_bug.cgi?id=227651
     5
     6        Reviewed by Sam Weinig.
     7
     8        * TestExpectations:
     9        * tests-options.json:
     10
    1112021-07-12  Eric Hutchison  <ehutchison@apple.com>
    212
  • trunk/LayoutTests/TestExpectations

    r279819 r279838  
    412412imported/w3c/web-platform-tests/html/webappapis/timers/negative-settimeout.any.worker.html [ DumpJSConsoleLogInStdErr ]
    413413imported/w3c/web-platform-tests/html/webappapis/user-prompts/print-during-beforeunload.html [ DumpJSConsoleLogInStdErr ]
     414imported/w3c/web-platform-tests/reporting/disconnect.html [ DumpJSConsoleLogInStdErr ]
    414415imported/w3c/web-platform-tests/streams/readable-streams/patched-global.any.html [ DumpJSConsoleLogInStdErr ]
    415416imported/w3c/web-platform-tests/streams/transform-streams/terminate.any.html [ DumpJSConsoleLogInStdErr ]
     
    440441imported/w3c/web-platform-tests/clipboard-apis/feature-policy/clipboard-read/clipboard-read-enabled-by-feature-policy.tentative.https.sub.html [ Skip ]
    441442imported/w3c/web-platform-tests/clipboard-apis/feature-policy/clipboard-read/clipboard-read-enabled-on-self-origin-by-feature-policy.tentative.https.sub.html [ Skip ]
     443imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-import.http.html [ Skip ]
     444imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-import.https.html [ Skip ]
     445imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-import-data.http.html [ Skip ]
     446imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-import-data.https.html [ Skip ]
     447imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-import.http.html [ Skip ]
     448imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-import.https.html [ Skip ]
     449imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-import-data.http.html [ Skip ]
     450imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-import-data.https.html [ Skip ]
     451imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-import.http.html [ Skip ]
     452imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-import.https.html [ Skip ]
     453imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-import-data.http.html [ Skip ]
     454imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-import-data.https.html [ Skip ]
     455imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-import.http.html [ Skip ]
     456imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-import.https.html [ Skip ]
     457imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-import-data.http.html [ Skip ]
     458imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-import-data.https.html [ Skip ]
     459imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-import.http.html [ Skip ]
     460imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-import.https.html [ Skip ]
     461imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-import-data.http.html [ Skip ]
     462imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-import-data.https.html [ Skip ]
     463imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-import.http.html [ Skip ]
     464imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-import.https.html [ Skip ]
     465imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-import-data.http.html [ Skip ]
     466imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-import-data.https.html [ Skip ]
     467imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-import.http.html [ Skip ]
     468imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-import.https.html [ Skip ]
     469imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-import-data.http.html [ Skip ]
     470imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-import-data.https.html [ Skip ]
     471imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-import.http.html [ Skip ]
     472imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-import.https.html [ Skip ]
     473imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-import-data.http.html [ Skip ]
     474imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-import-data.https.html [ Skip ]
     475imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-import.http.html [ Skip ]
     476imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-import.https.html [ Skip ]
     477imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-import-data.http.html [ Skip ]
     478imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-import-data.https.html [ Skip ]
     479imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-import.http.html [ Skip ]
     480imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-import.https.html [ Skip ]
     481imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-import-data.http.html [ Skip ]
     482imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-import-data.https.html [ Skip ]
     483imported/w3c/web-platform-tests/content-security-policy/inheritance/history-iframe.sub.html [ Skip ]
     484imported/w3c/web-platform-tests/content-security-policy/inheritance/javascript-url-open-in-main-window.html [ Skip ]
     485imported/w3c/web-platform-tests/content-security-policy/inheritance/javascript-url-srcdoc-cross-origin-iframe-inheritance.html [ Skip ]
     486imported/w3c/web-platform-tests/content-security-policy/inheritance/location-reload.html [ Skip ]
     487imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicatedworker-connect-src.html [ Skip ]
     488imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicatedworker-script-src.html [ Skip ]
     489imported/w3c/web-platform-tests/content-security-policy/inside-worker/serviceworker-connect-src.https.sub.html [ Skip ]
     490imported/w3c/web-platform-tests/content-security-policy/inside-worker/serviceworker-script-src.https.sub.html [ Skip ]
     491imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-blocked-by-default.html [ Skip ]
     492imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-header-blocked-by-default.html [ Skip ]
     493imported/w3c/web-platform-tests/content-security-policy/reporting-api/report-to-directive-allowed-in-meta.https.sub.html [ Skip ]
     494imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_double_policy_honor_source_expressions.sub.html [ Skip ]
     495imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/img-src-redirect.sub.html [ Skip ]
     496imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/source-file-blob-scheme.html [ Skip ]
     497imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/source-file-data-scheme.html [ Skip ]
    442498imported/w3c/web-platform-tests/cookies/domain/domain-attribute-host-with-and-without-leading-period.sub.https.html [ Skip ]
    443499imported/w3c/web-platform-tests/cookies/domain/domain-attribute-host-with-leading-period.sub.https.html [ Skip ]
     
    547603imported/w3c/web-platform-tests/html/semantics/interactive-elements/the-summary-element/anchor-with-inline-element.html [ Skip ]
    548604imported/w3c/web-platform-tests/html/semantics/scripting-1/the-script-element/json-module/parse-error.tentative.html [ Skip ]
     605imported/w3c/web-platform-tests/reporting/path-absolute-endpoint.https.sub.html [ Skip ]
    549606imported/w3c/web-platform-tests/workers/interfaces/WorkerGlobalScope/onerror/message-module-Error.html [ Skip ]
    550607[ Debug ] imported/w3c/web-platform-tests/css/css-backgrounds/background-size/background-size-near-zero-svg.html [ Skip ]
     
    665722# Newly imported WPT tests that are flaky.
    666723webkit.org/b/227649 imported/w3c/web-platform-tests/beacon/beacon-basic.https.window.html [ Failure Pass ]
     724imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-audio.https.html [ Failure Pass ]
     725imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/script-tag.http.html [ Failure Pass ]
     726imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/script-tag.https.html [ Failure Pass ]
     727imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-audio.https.html [ Failure Pass ]
     728imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/script-tag.http.html [ Failure Pass ]
     729imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/script-tag.https.html [ Failure Pass ]
     730imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-audio-import-data.https.html [ Failure Pass ]
     731imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-audio.https.html [ Failure Pass ]
     732imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/script-tag.http.html [ Failure Pass ]
     733imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/script-tag.https.html [ Failure Pass ]
     734imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-audio-import-data.https.html [ Failure Pass ]
     735imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-audio.https.html [ Failure Pass ]
     736imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/script-tag.http.html [ Failure Pass ]
     737imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/script-tag.https.html [ Failure Pass ]
     738imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-audio-import-data.https.html [ Failure Pass ]
     739imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-audio.https.html [ Failure Pass ]
     740imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-audio.https.html [ Failure Pass ]
     741imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/script-tag.http.html [ Failure Pass ]
     742imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/script-tag.https.html [ Failure Pass ]
     743imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-audio.https.html [ Failure Pass ]
     744imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/script-tag.http.html [ Failure Pass ]
     745imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/script-tag.https.html [ Failure Pass ]
     746imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-audio-import-data.https.html [ Failure Pass ]
     747imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-audio.https.html [ Failure Pass ]
     748imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/script-tag.http.html [ Failure Pass ]
     749imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/script-tag.https.html [ Failure Pass ]
     750imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-audio-import-data.https.html [ Failure Pass ]
     751imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-audio.https.html [ Failure Pass ]
     752imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/script-tag.http.html [ Failure Pass ]
     753imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/script-tag.https.html [ Failure Pass ]
     754imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-audio-import-data.https.html [ Failure Pass ]
     755imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-audio.https.html [ Failure Pass ]
    667756imported/w3c/web-platform-tests/cookies/name/name.html [ Failure Pass ]
    668757imported/w3c/web-platform-tests/cookies/prefix/__secure.header.https.html [ Failure Pass ]
     
    705794imported/w3c/web-platform-tests/html/semantics/embedded-content/the-iframe-element/cross-origin-to-whom-part-2.window.html [ Failure Pass ]
    706795imported/w3c/web-platform-tests/html/semantics/forms/form-submission-0/multipart-formdata.window.html [ Failure Pass ]
     796imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-works-on-frame-ancestors.https.sub.html [ Failure Pass ]
    707797imported/w3c/web-platform-tests/user-timing/clearMarks.html [ Failure Pass ]
    708798imported/w3c/web-platform-tests/user-timing/mark.html [ Failure Pass ]
     
    841931imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-header-allowed.html [ Skip ]
    842932imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-header-blocked.html [ Skip ]
    843 imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicated-inheritance.html [ Skip ]
    844 imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicated-script.html [ Skip ]
    845933imported/w3c/web-platform-tests/content-security-policy/style-src/stylenonce-allowed.sub.html [ Skip ]
    846934imported/w3c/web-platform-tests/content-security-policy/style-src/stylehash-basic-blocked.sub.html [ Skip ]
     
    849937imported/w3c/web-platform-tests/content-security-policy/style-src/stylenonce-blocked.sub.html [ Skip ]
    850938imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-inline-style-nonce-blocked-error-event.html [ Skip ]
    851 imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-mismatched-url.html [ Skip ]
    852 imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-mismatched-data.html [ Skip ]
    853 imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-notype-data.html [ Skip ]
    854 imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-nourl-blocked.html [ Skip ]
    855 imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-notype-url.html [ Skip ]
    856 imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-empty.sub.html [ Skip ]
    857939imported/w3c/web-platform-tests/content-security-policy/child-src/child-src-cross-origin-load.sub.html [ Skip ]
    858940imported/w3c/web-platform-tests/content-security-policy/inheritance/document-write-iframe.html [ Skip ]
  • trunk/LayoutTests/imported/w3c/ChangeLog

    r279819 r279838  
     12021-07-12  Chris Dumez  <cdumez@apple.com>
     2
     3        Resync content-security-policy web-platform-tests from upstream
     4        https://bugs.webkit.org/show_bug.cgi?id=227651
     5
     6        Reviewed by Sam Weinig.
     7
     8        Resync content-security-policy web-platform-tests from upstream 2c19d6ee62676ac90146.
     9
     10        * resources/import-expectations.json:
     11        * resources/resource-files.json:
     12        * web-platform-tests/content-security-policy/*: Updated.
     13        * web-platform-tests/reporting/*: Imported.
     14
    1152021-07-12  Rob Buis  <rbuis@igalia.com>
    216
  • trunk/LayoutTests/imported/w3c/resources/import-expectations.json

    r279769 r279838  
    379379    "web-platform-tests/referrer-policy": "import",
    380380    "web-platform-tests/remote-playback": "import",
     381    "web-platform-tests/reporting": "import",
    381382    "web-platform-tests/requestidlecallback": "import",
    382383    "web-platform-tests/resize-observer": "import",
  • trunk/LayoutTests/imported/w3c/resources/resource-files.json

    r279819 r279838  
    9999        "web-platform-tests/compat/webkit-box-fixed-position-child.html",
    100100        "web-platform-tests/content-security-policy/README.html",
     101        "web-platform-tests/content-security-policy/embedded-enforcement/support/embed-img-and-message-top.html",
    101102        "web-platform-tests/content-security-policy/embedded-enforcement/support/executor.html",
    102103        "web-platform-tests/content-security-policy/form-action/support/post-message-to-opener.sub.html",
     
    112113        "web-platform-tests/content-security-policy/generic/support/sandboxed-eval.sub.html",
    113114        "web-platform-tests/content-security-policy/inheritance/support/empty.html",
     115        "web-platform-tests/content-security-policy/inheritance/support/iframe-do.sub.html",
     116        "web-platform-tests/content-security-policy/inheritance/support/javascript-url-srcdoc-cross-origin-iframe-inheritance-helper.sub.html",
     117        "web-platform-tests/content-security-policy/inheritance/support/message-opener-and-navigate-back.html",
     118        "web-platform-tests/content-security-policy/inheritance/support/message-top-and-navigate-back.html",
     119        "web-platform-tests/content-security-policy/inheritance/support/navigate-parent-to-blob.html",
    114120        "web-platform-tests/content-security-policy/inheritance/support/navigate-self-to-blob.html",
     121        "web-platform-tests/content-security-policy/inheritance/support/navigate-self-to-javascript.html",
     122        "web-platform-tests/content-security-policy/inheritance/support/postmessage-opener.html",
     123        "web-platform-tests/content-security-policy/inheritance/support/postmessage-top.html",
    115124        "web-platform-tests/content-security-policy/inheritance/support/srcdoc-child-frame.html",
    116125        "web-platform-tests/content-security-policy/navigate-to/support/post_message_to_frame_owner.html",
     
    119128        "web-platform-tests/content-security-policy/navigate-to/support/spv-test-iframe3.sub.html",
    120129        "web-platform-tests/content-security-policy/navigation/support/frame-with-csp.sub.html",
     130        "web-platform-tests/content-security-policy/reporting-api/support/non-embeddable-frame.html",
    121131        "web-platform-tests/content-security-policy/reporting/support/generate-csp-report.html",
     132        "web-platform-tests/content-security-policy/sandbox/support/empty.html",
    122133        "web-platform-tests/content-security-policy/sandbox/support/sandboxed-data-iframe.sub.html",
    123134        "web-platform-tests/content-security-policy/sandbox/support/sandboxed-eval.sub.html",
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/README.html

    r254133 r279838  
    7272Pragma: no-cache
    7373Set-Cookie: <span class=highlight2>script-src-1_1</span>={{$id:uuid()}}; Path=<span class=highlight2>/content-security-policy/script-src/</span>
    74 Content-Security-Policy: <span class=highlight1>script-src 'self'</span>; report-uri  <span class=highlight2>..</span>/support/report.py?op=put&reportID;={{$id}}
     74Content-Security-Policy: <span class=highlight1>script-src 'self'</span>; report-uri  <span class=highlight2></span>/reporting/resources/report.py?op=put&reportID;={{$id}}
    7575        </code></pre>
    7676    <p>This sets some headers to prevent caching (just so we are more likely to see our latest changes if we're actively developing this test) sets a cookie (more on that later) and sets the relevant <span class=code>Content-Security-Policy</span> header for our test case.</p>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/base-uri/report-uri-does-not-respect-base-uri.sub.html.sub.headers

    r246330 r279838  
    33Pragma: no-cache
    44Set-Cookie: report-uri-does-not-respect-base-uri={{$id:uuid()}}; Path=/content-security-policy/base-uri
    5 Content-Security-Policy: script-src 'self' 'unsafe-inline'; img-src 'none'; report-uri ../support/report.py?op=put&reportID={{$id}}
     5Content-Security-Policy: script-src 'self' 'unsafe-inline'; img-src 'none'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/blob/blob-urls-match-blob.sub.html

    r246330 r279838  
    44<head>
    55    <!-- Programmatically converted from a WebKit Reftest, please forgive resulting idiosyncracies.-->
    6     <meta http-equiv="Content-Security-Policy" content="script-src 'self' 'unsafe-inline' blob:; connect-src 'self';">   
     6    <meta http-equiv="Content-Security-Policy" content="script-src 'self' 'unsafe-inline' blob:; connect-src 'self';">
    77    <title>blob-urls-match-blob</title>
    88    <script src="/resources/testharness.js"></script>
     
    2020            log("FAIL");
    2121        });
    22    
     22
    2323        function pass() {
    2424            log("PASS (1/1)");
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/blob/self-doesnt-match-blob.sub.html

    r246330 r279838  
    2121            log("violated-directive=" + e.violatedDirective);
    2222        });
    23    
     23
    2424        try {
    2525            var blob = new Blob([
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/blob/star-doesnt-match-blob.sub.html

    r246330 r279838  
    2121            log("violated-directive=" + e.violatedDirective);
    2222        });
    23    
     23
    2424        try {
    2525            var blob = new Blob([
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/child-src/child-src-about-blank-allowed-by-default.sub.html

    r246330 r279838  
    1616        window.addEventListener("securitypolicyviolation", t.unreached_func("Should not have fired any events"));
    1717    </script>
    18    
     18
    1919    <iframe src="about:blank"></iframe>
    2020    <object type="text/html" data="about:blank"></object>
    2121
    2222    <div id="log"></div>
    23    
     23
    2424    <script>
    2525        t.done();
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/child-src/child-src-about-blank-allowed-by-scheme.sub.html

    r246330 r279838  
    1414        window.addEventListener("securitypolicyviolation", t.unreached_func("Should not have fired any events"));
    1515    </script>
    16    
     16
    1717    <iframe src="about:blank"></iframe>
    1818    <div id="log"></div>
    19    
     19
    2020    <script>
    2121        t.done();
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/child-src/child-src-allowed.sub.html

    r246330 r279838  
    1212            alert_assert(event.data);
    1313        }, false);
    14        
     14
    1515        window.addEventListener("securitypolicyviolation", function(e) {
    1616            alert_assert("Fail");
     
    2828                for (var i = 0; i < expected_alerts.length; i++) {
    2929                    if (expected_alerts[i] == msg) {
    30                         assert_true(expected_alerts[i] == msg);
     30                        assert_equals(expected_alerts[i], msg);
    3131                        expected_alerts.splice(i, 1);
    3232                        if (expected_alerts.length == 0) {
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/child-src/child-src-blocked.sub.html

    r246330 r279838  
    1313            alert_assert(event.data);
    1414        }, false);
    15        
     15
    1616        window.addEventListener("securitypolicyviolation", function(e) {
    1717            log("violated-directive=" + e.violatedDirective);
     
    2626                for (var i = 0; i < expected_alerts.length; i++) {
    2727                    if (expected_alerts[i] == msg) {
    28                         assert_true(expected_alerts[i] == msg);
     28                        assert_equals(expected_alerts[i], msg);
    2929                        expected_alerts.splice(i, 1);
    3030                        if (expected_alerts.length == 0) {
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/child-src/child-src-conflicting-frame-src.sub.html

    r246330 r279838  
    2424                for (var i = 0; i < expected_alerts.length; i++) {
    2525                    if (expected_alerts[i] == msg) {
    26                         assert_true(expected_alerts[i] == msg);
     26                        assert_equals(expected_alerts[i], msg);
    2727                        expected_alerts.splice(i, 1);
    2828                        if (expected_alerts.length == 0) {
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/child-src/child-src-cross-origin-load.sub.html

    r246330 r279838  
    2929                for (var i = 0; i < expected_alerts.length; i++) {
    3030                    if (expected_alerts[i] == msg) {
    31                         assert_true(expected_alerts[i] == msg);
     31                        assert_equals(expected_alerts[i], msg);
    3232                        expected_alerts.splice(i, 1);
    3333                        if (expected_alerts.length == 0) {
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/child-src/child-src-redirect-blocked.sub.html

    r246330 r279838  
    2626                for (var i = 0; i < expected_alerts.length; i++) {
    2727                    if (expected_alerts[i] == msg) {
    28                         assert_true(expected_alerts[i] == msg);
     28                        assert_equals(expected_alerts[i], msg);
    2929                        expected_alerts.splice(i, 1);
    3030                        if (expected_alerts.length == 0) {
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/connect-src/shared-worker-connect-src-allowed.sub.html

    r246330 r279838  
    1717        log("violated-directive=" + e.violatedDirective);
    1818    });
    19    
     19
    2020    if(typeof SharedWorker != 'function') {
    2121        t_log.set_status(t_alert.NOTRUN, "No SharedWorker, cannot run test.");
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/connect-src/shared-worker-connect-src-blocked.sub.html

    r246330 r279838  
    99    <script src="/resources/testharnessreport.js"></script>
    1010    <script src='../support/logTest.sub.js?logs=["xhr blocked","TEST COMPLETE"]'></script>
    11     <script src='../support/alertAssert.sub.js?alerts=[]'></script>   
     11    <script src='../support/alertAssert.sub.js?alerts=[]'></script>
    1212</head>
    1313
     
    2323            log("Fail");
    2424       });
    25    
     25
    2626      if(typeof SharedWorker != 'function') {
    2727          t_log.set_status(t_log.NOTRUN, "No SharedWorker, cannot run test.");
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/connect-src/worker-connect-src-allowed.sub.html

    r246330 r279838  
    1818            log('Fail');
    1919        });
    20    
     20
    2121        try {
    2222            var worker = new Worker('/content-security-policy/connect-src/support/worker-make-xhr.sub.js');
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/connect-src/worker-connect-src-blocked.sub.html

    r246330 r279838  
    2222            log('Fail');
    2323        });
    24    
     24
    2525        try {
    2626            var worker = new Worker('/content-security-policy/connect-src/support/worker-make-xhr-blocked.sub.js');
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/connect-src/worker-from-guid.sub.html

    r246330 r279838  
    4040                "  xhr.open(" +
    4141                "   'GET'," +
    42                 "   'http:///content-security-policy/support/fail.asis'," + 
     42                "   'http:///content-security-policy/support/fail.asis'," +
    4343                "    true" +
    4444                "  );" +
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/allow_csp_from-header.html

    r263605 r279838  
    1010  <script>
    1111    var tests = [
    12       { "name": "Same origin iframes are always allowed.", 
     12      { "name": "Same origin iframes are always allowed.",
    1313        "origin": Host.SAME_ORIGIN,
    14         "csp": "style-src 'unsafe-inline'; script-src 'unsafe-inline'", 
     14        "csp": "style-src 'unsafe-inline'; script-src 'unsafe-inline'",
    1515        "allow_csp_from": "¢¥§",
    1616        "expected": IframeLoad.EXPECT_LOAD,
    1717        "blockedURI": null},
    18       { "name": "Same origin iframes are allowed even if the Allow-CSP-From is empty.", 
     18      { "name": "Same origin iframes are allowed even if the Allow-CSP-From is empty.",
    1919        "origin": Host.SAME_ORIGIN,
    20         "csp": "style-src 'unsafe-inline'; script-src 'unsafe-inline'", 
     20        "csp": "style-src 'unsafe-inline'; script-src 'unsafe-inline'",
    2121        "allow_csp_from": "",
    2222        "expected": IframeLoad.EXPECT_LOAD,
    2323        "blockedURI": null},
    24       { "name": "Same origin iframes are allowed even if the Allow-CSP-From is not present.", 
     24      { "name": "Same origin iframes are allowed even if the Allow-CSP-From is not present.",
    2525        "origin": Host.SAME_ORIGIN,
    26         "csp": "style-src 'unsafe-inline'; script-src 'unsafe-inline'", 
     26        "csp": "style-src 'unsafe-inline'; script-src 'unsafe-inline'",
    2727        "allow_csp_from": null,
    2828        "expected": IframeLoad.EXPECT_LOAD,
    2929        "blockedURI": null},
    30       { "name": "Same origin iframes are allowed even if Allow-CSP-From does not match origin.", 
     30      { "name": "Same origin iframes are allowed even if Allow-CSP-From does not match origin.",
    3131        "origin": Host.SAME_ORIGIN,
    32         "csp": "style-src 'unsafe-inline'; script-src 'unsafe-inline'", 
     32        "csp": "style-src 'unsafe-inline'; script-src 'unsafe-inline'",
    3333        "allow_csp_from": "http://example.com:888",
    3434        "expected": IframeLoad.EXPECT_LOAD,
    3535        "blockedURI": null},
    36       { "name": "Cross origin iframe with an empty Allow-CSP-From header gets blocked.", 
     36      { "name": "Cross origin iframe with an empty Allow-CSP-From header gets blocked.",
    3737        "origin": Host.CROSS_ORIGIN,
    38         "csp": "script-src 'unsafe-inline'", 
     38        "csp": "script-src 'unsafe-inline'",
    3939        "allow_csp_from": "",
    4040        "expected": IframeLoad.EXPECT_BLOCK,
    4141        "blockedURI": null},
    42       { "name": "Cross origin iframe without Allow-CSP-From header gets blocked.", 
     42      { "name": "Cross origin iframe without Allow-CSP-From header gets blocked.",
    4343        "origin": Host.CROSS_ORIGIN,
    44         "csp": "script-src 'unsafe-inline'", 
     44        "csp": "script-src 'unsafe-inline'",
    4545        "allow_csp_from": null,
    4646        "expected": IframeLoad.EXPECT_BLOCK,
     
    4848      { "name": "Cross origin iframe with correct Allow-CSP-From header is allowed.",
    4949        "origin": Host.CROSS_ORIGIN,
    50         "csp": "style-src 'unsafe-inline'; script-src 'unsafe-inline'", 
     50        "csp": "style-src 'unsafe-inline'; script-src 'unsafe-inline'",
    5151        "allow_csp_from": getOrigin(),
    5252        "expected": IframeLoad.EXPECT_LOAD,
    5353        "blockedURI": null},
    54       { "name": "Iframe with improper Allow-CSP-From header gets blocked.", 
     54      { "name": "Iframe with improper Allow-CSP-From header gets blocked.",
    5555        "origin": Host.CROSS_ORIGIN,
    56         "csp": "script-src 'unsafe-inline'", 
     56        "csp": "script-src 'unsafe-inline'",
    5757        "allow_csp_from": "* ¢¥§",
    5858        "expected": IframeLoad.EXPECT_BLOCK,
     
    6060      { "name": "Allow-CSP-From header with a star value allows cross origin frame.",
    6161        "origin": Host.CROSS_ORIGIN,
    62         "csp": "script-src 'unsafe-inline'", 
     62        "csp": "script-src 'unsafe-inline'",
    6363        "allow_csp_from": "*",
    6464        "expected": IframeLoad.EXPECT_LOAD,
    6565        "blockedURI": null},
    66       { "name": "Star Allow-CSP-From header enforces EmbeddingCSP.", 
     66      { "name": "Star Allow-CSP-From header enforces EmbeddingCSP.",
    6767        "origin": Host.CROSS_ORIGIN,
    68         "csp": "script-src 'nonce-123'", 
     68        "csp": "script-src 'nonce-123'",
    6969        "allow_csp_from": "*",
    7070        "expected": IframeLoad.EXPECT_LOAD,
    7171        "blockedURI": "inline"},
    72       { "name": "Allow-CSP-From header enforces EmbeddingCSP.", 
     72      { "name": "Allow-CSP-From header enforces EmbeddingCSP.",
    7373        "origin": Host.CROSS_ORIGIN,
    74         "csp": "style-src 'none'; script-src 'nonce-123'", 
     74        "csp": "style-src 'none'; script-src 'nonce-123'",
    7575        "allow_csp_from": getOrigin(),
    7676        "expected": IframeLoad.EXPECT_LOAD,
    7777        "blockedURI": "inline"},
     78      { "name": "'self' in blanket enforced EmbeddingCSP matches the target response origin.",
     79        "origin": Host.CROSS_ORIGIN,
     80        "csp": "img-src 'self'",
     81        "allow_csp_from": "*",
     82        "expected": IframeLoad.EXPECT_LOAD,
     83        "blockedURI": null},
    7884    ];
    7985
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/required-csp-header-cascade.html

    r246330 r279838  
    3535        "expected1": null,
    3636        "expected2": "script-src 'unsafe-inline'; style-src 'self';"},
    37       { "name": "Test invalid policy on first iframe (bad directive)",
    38         "csp1": "default-src http://example.com; invalid-policy-name http://example.com",
     37      { "name": "Test invalid policy on first iframe (bad directive name)",
     38        "csp1": "default-src http://example.com; i//nvalid-policy-name http://example.com",
    3939        "csp2": "script-src 'unsafe-inline'; style-src 'self';",
    4040        "expected1": null,
     
    4545        "expected1": null,
    4646        "expected2": "script-src 'unsafe-inline'; style-src 'self';"},
    47       { "name": "Test invalid policy on second iframe (bad directive)",
     47      { "name": "Test invalid policy on second iframe (bad directive name)",
    4848        "csp1": "script-src 'unsafe-inline'; style-src 'self';",
    49         "csp2": "default-src http://example.com; invalid-policy-name http://example.com",
     49        "csp2": "default-src http://example.com; i//nvalid-policy-name http://example.com",
    5050        "expected1": "script-src 'unsafe-inline'; style-src 'self';",
    5151        "expected2": "script-src 'unsafe-inline'; style-src 'self';"},
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/required_csp-header-crlf.html

    r246330 r279838  
    22<html>
    33<head>
    4 <title>Embedded Enforcement: Sec-Required-CSP header.</title>
     4  <title>Embedded Enforcement: Sec-Required-CSP header.</title>
     5  <!--
     6    This test is creating and navigating several iframes. This can exceed the
     7    "short" timeout". See https://crbug.com/1091896
     8  -->
     9  <meta name="timeout" content="long">
    510  <script src="/resources/testharness.js"></script>
    611  <script src="/resources/testharnessreport.js"></script>
     
    1217      // CRLF characters
    1318      { "name": "\\r\\n character after directive name",
    14         "csp": "script-src\r\n'unsafe-inline'",
     19        "csp": "style-src\r\n'unsafe-inline'",
    1520        "expected": null },
    1621      { "name": "\\r\\n character in directive value",
    17         "csp": "script-src 'unsafe-inline'\r\n'unsafe-eval'",
     22        "csp": "style-src 'unsafe-inline'\r\n'unsafe-eval'",
    1823        "expected": null },
    1924      { "name": "\\n character after directive name",
    20         "csp": "script-src\n'unsafe-inline'",
     25        "csp": "style-src\n'unsafe-inline'",
    2126        "expected": null },
    2227      { "name": "\\n character in directive value",
    23         "csp": "script-src 'unsafe-inline'\n'unsafe-eval'",
     28        "csp": "style-src 'unsafe-inline'\n'unsafe-eval'",
    2429        "expected": null },
    2530      { "name": "\\r character after directive name",
    26         "csp": "script-src\r'unsafe-inline'",
     31        "csp": "style-src\r'unsafe-inline'",
    2732        "expected": null },
    2833      { "name": "\\r character in directive value",
    29         "csp": "script-src 'unsafe-inline'\r'unsafe-eval'",
    30         "expected": null },
    31        
    32       // HTML encoded CRLF characters
    33       { "name": "%0D%0A character after directive name",
    34         "csp": "script-src%0D%0A'unsafe-inline'",
    35         "expected": null },
    36       { "name": "%0D%0A character in directive value",
    37         "csp": "script-src 'unsafe-inline'%0D%0A'unsafe-eval'",
    38         "expected": null },
    39       { "name": "%0A character after directive name",
    40         "csp": "script-src%0A'unsafe-inline'",
    41         "expected": null },
    42       { "name": "%0A character in directive value",
    43         "csp": "script-src 'unsafe-inline'%0A'unsafe-eval'",
    44         "expected": null },
    45       { "name": "%0D character after directive name",
    46         "csp": "script-src%0D'unsafe-inline'",
    47         "expected": null },
    48       { "name": "%0D character in directive value",
    49         "csp": "script-src 'unsafe-inline'%0D'unsafe-eval'",
     34        "csp": "style-src 'unsafe-inline'\r'unsafe-eval'",
    5035        "expected": null },
    5136
    5237      // Attempt HTTP Header injection
    5338      { "name": "Attempt injecting after directive name using \\r\\n",
    54         "csp": "script-src\r\nTest-Header-Injection: dummy",
     39        "csp": "style-src\r\nTest-Header-Injection: dummy",
    5540        "expected": null },
    5641      { "name": "Attempt injecting after directive name using \\r",
    57         "csp": "script-src\rTest-Header-Injection: dummy",
     42        "csp": "style-src\rTest-Header-Injection: dummy",
    5843        "expected": null },
    5944      { "name": "Attempt injecting after directive name using \\n",
    60         "csp": "script-src\nTest-Header-Injection: dummy",
     45        "csp": "style-src\nTest-Header-Injection: dummy",
    6146        "expected": null },
    6247
    6348      { "name": "Attempt injecting after directive value using \\r\\n",
    64         "csp": "script-src example.com\r\nTest-Header-Injection: dummy",
     49        "csp": "style-src example.com\r\nTest-Header-Injection: dummy",
    6550        "expected": null },
    6651      { "name": "Attempt injecting after directive value using \\r",
    67         "csp": "script-src example.com\rTest-Header-Injection: dummy",
     52        "csp": "style-src example.com\rTest-Header-Injection: dummy",
    6853        "expected": null },
    6954      { "name": "Attempt injecting after directive value using \\n",
    70         "csp": "script-src example.com\nTest-Header-Injection: dummy",
     55        "csp": "style-src example.com\nTest-Header-Injection: dummy",
    7156        "expected": null },
    7257
    7358      { "name": "Attempt injecting after semicolon using \\r\\n",
    74         "csp": "script-src example.com;\r\nTest-Header-Injection: dummy",
     59        "csp": "style-src example.com;\r\nTest-Header-Injection: dummy",
    7560        "expected": null },
    7661      { "name": "Attempt injecting after semicolon using \\r",
    77         "csp": "script-src example.com;\rTest-Header-Injection: dummy",
     62        "csp": "style-src example.com;\rTest-Header-Injection: dummy",
    7863        "expected": null },
    7964      { "name": "Attempt injecting after semicolon using \\n",
    80         "csp": "script-src example.com;\nTest-Header-Injection: dummy",
     65        "csp": "style-src example.com;\nTest-Header-Injection: dummy",
    8166        "expected": null },
    8267
    8368      { "name": "Attempt injecting after space between name and value using \\r\\n",
    84         "csp": "script-src \r\nTest-Header-Injection: dummy",
     69        "csp": "style-src \r\nTest-Header-Injection: dummy",
    8570        "expected": null },
    8671      { "name": "Attempt injecting after space between name and value using \\r",
    87         "csp": "script-src \rTest-Header-Injection: dummy",
     72        "csp": "style-src \rTest-Header-Injection: dummy",
    8873        "expected": null },
    8974      { "name": "Attempt injecting after space between name and value using \\n",
    90         "csp": "script-src \nTest-Header-Injection: dummy",
     75        "csp": "style-src \nTest-Header-Injection: dummy",
    9176        "expected": null },
    92 
    93       // Attempt HTTP Header injection using URL encoded characters
    94       { "name": "Attempt injecting after directive name using %0D%0A",
    95         "csp": "script-src%0D%0ATest-Header-Injection: dummy",
    96         "expected": null },
    97       { "name": "Attempt injecting after directive name using %0D",
    98         "csp": "script-src%0DTest-Header-Injection: dummy",
    99         "expected": null },
    100       { "name": "Attempt injecting after directive name using %0A",
    101         "csp": "script-src%0ATest-Header-Injection: dummy",
    102         "expected": null },
    103 
    104       { "name": "Attempt injecting after directive value using %0D%0A",
    105         "csp": "script-src example.com%0D%0ATest-Header-Injection: dummy",
    106         "expected": null },
    107       { "name": "Attempt injecting after directive value using %0D",
    108         "csp": "script-src example.com%0DTest-Header-Injection: dummy",
    109         "expected": null },
    110       { "name": "Attempt injecting after directive value using %0A",
    111         "csp": "script-src example.com%0ATest-Header-Injection: dummy",
    112         "expected": null },
    113 
    114       { "name": "Attempt injecting after semicolon using %0D%0A",
    115         "csp": "script-src example.com;%0D%0ATest-Header-Injection: dummy",
    116         "expected": null },
    117       { "name": "Attempt injecting after semicolon using %0D",
    118         "csp": "script-src example.com;%0DTest-Header-Injection: dummy",
    119         "expected": null },
    120       { "name": "Attempt injecting after semicolon using %0A",
    121         "csp": "script-src example.com;%0ATest-Header-Injection: dummy",
    122         "expected": null },
    123 
    124       { "name": "Attempt injecting after space between name and value using %0D%0A",
    125         "csp": "script-src %0D%0ATest-Header-Injection: dummy",
    126         "expected": null },
    127       { "name": "Attempt injecting after space between name and value using %0D",
    128         "csp": "script-src %0DTest-Header-Injection: dummy",
    129         "expected": null },
    130       { "name": "Attempt injecting after space between name and value using %0A",
    131         "csp": "script-src %0ATest-Header-Injection: dummy",
    132         "expected": null },
    133 
    13477    ];
    13578
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/required_csp-header.html

    r263605 r279838  
    2525        "csp": "script-src 'unsafe-inline'",
    2626        "expected":  "script-src 'unsafe-inline'" },
    27       { "name": "Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - gibberish csp",
     27      { "name": "Wrong but allowed value of `csp` should still trigger sending Sec-Required-CSP Header - gibberish csp",
    2828        "csp": "completely wrong csp",
     29        "expected": "completely wrong csp" },
     30      { "name": "Wrong but allowed value of `csp` should still trigger sending Sec-Required-CSP Header - unknown policy name",
     31        "csp": "invalid-policy-name http://example.com",
     32        "expected": "invalid-policy-name http://example.com" },
     33      { "name": "Wrong but allowed value of `csp` should still trigger sending Sec-Required-CSP Header - unknown policy name in multiple directives",
     34        "csp": "media-src http://example.com; invalid-policy-name http://example.com",
     35        "expected": "media-src http://example.com; invalid-policy-name http://example.com" },
     36      { "name": "Wrong but allowed value of `csp` should still trigger sending Sec-Required-CSP Header - misspeled 'none'",
     37        "csp": "media-src 'non'",
     38        "expected": "media-src 'non'" },
     39      { "name": "Wrong but allowed value of `csp` should still trigger sending Sec-Required-CSP Header - query values in path",
     40        "csp": "script-src 'unsafe-inline' 127.0.0.1:8000/path?query=string",
     41        "expected": "script-src 'unsafe-inline' 127.0.0.1:8000/path?query=string" },
     42      { "name": "Wrong but allowed value of `csp` should still trigger sending Sec-Required-CSP Header - missing semicolon",
     43        "csp": "script-src 'unsafe-inline' 'self' object-src 'self' style-src *",
     44        "expected": "script-src 'unsafe-inline' 'self' object-src 'self' style-src *" },
     45      { "name": "Wrong and dangerous value of `csp` should not trigger sending Sec-Required-CSP Header - comma separated",
     46        "csp": "script-src 'unsafe-inline' 'self', object-src 'none'",
    2947        "expected": null },
    30       { "name": "Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - unknown policy name",
    31         "csp": "invalid-policy-name http://example.com",
     48      { "name": "Wrong and dangerous value of `csp` should not trigger sending Sec-Required-CSP Header - invalid characters in directive names",
     49        // script-src 127.0.0.1:8000
     50        "csp": "script-src 'unsafe-inline' &#x31;&#x32;&#x37;&#x2E;&#x30;&#x2E;&#x30;&#x2E;&#x31;&#x3A;&#x38;&#x30;&#x30;&#x30;",
    3251        "expected": null },
    33       { "name": "Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - unknown policy name in multiple directives",
    34         "csp": "default-src http://example.com; invalid-policy-name http://example.com",
     52      { "name": "Wrong and dangerous value of `csp` should not trigger sending Sec-Required-CSP Header - invalid character in directive name",
     53        // script-src 127.0.0.1:8000
     54        "csp": "media-src%20127.0.0.1%3A8000",
    3555        "expected": null },
    36       { "name": "Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - misspeled 'none'",
    37         "csp": "default-src 'non'",
    38         "expected": null },
    39       { "name": "Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - query values in path",
    40         "csp": "script-src 127.0.0.1:8000/path?query=string",
    41         "expected": null },
    42       { "name": "Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - missing semicolon",
    43         "csp": "script-src 'self' object-src 'self' style-src *",
    44         "expected": null },
    45       { "name": "Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - comma separated",
    46         "csp": "script-src 'none', object-src 'none'",
    47         "expected": null },
    48       { "name": "Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - html encoded string",
    49         // script-src 127.0.0.1:8000
    50         "csp": "script-src &#x31;&#x32;&#x37;&#x2E;&#x30;&#x2E;&#x30;&#x2E;&#x31;&#x3A;&#x38;&#x30;&#x30;&#x30;",
    51         "expected": null },
    52       { "name": "Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - url encoded string",
    53         // script-src 127.0.0.1:8000
    54         "csp": "script-src%20127.0.0.1%3A8000",
    55         "expected": null },
    56       { "name": "Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - report-uri present",
     56      { "name": "Wrong and dangerous value of `csp` should not trigger sending Sec-Required-CSP Header - report-uri present",
    5757        "csp": "script-src 'unsafe-inline'; report-uri resources/dummy-report.php",
    5858        "expected": null },
    59       { "name": "Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - report-to present",
     59      { "name": "Wrong and dangerous value of `csp` should not trigger sending Sec-Required-CSP Header - report-to present",
    6060        "csp": "script-src 'unsafe-inline'; report-to resources/dummy-report.php",
    6161        "expected": null },
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-general.html

    r263605 r279838  
    1414    // return false negatives.
    1515    var tests = [
    16       { "name": "If there is no required csp, iframe should load.", 
    17         "required_csp": null, 
     16      { "name": "If there is no required csp, iframe should load.",
     17        "required_csp": null,
    1818        "returned_csp": null,
    1919        "expected": IframeLoad.EXPECT_LOAD },
    20       { "name": "Iframe with empty returned CSP should be blocked.", 
    21         "required_csp": "style-src 'none';", 
     20      { "name": "Iframe with empty returned CSP should be blocked.",
     21        "required_csp": "style-src 'none';",
    2222        "returned_csp": null,
    2323        "expected": IframeLoad.EXPECT_BLOCK },
    24       { "name": "Iframe with matching CSP should load.", 
    25         "required_csp": "style-src 'none'; script-src 'unsafe-inline'", 
    26         "returned_csp": "style-src 'none'; script-src 'unsafe-inline'", 
     24      { "name": "Iframe with matching CSP should load.",
     25        "required_csp": "style-src 'none'; script-src 'unsafe-inline'",
     26        "returned_csp": "style-src 'none'; script-src 'unsafe-inline'",
    2727        "expected": IframeLoad.EXPECT_LOAD },
    28       { "name": "Iframe with more restricting CSP should load.", 
    29         "required_csp": "script-src 'nonce-abc' 'nonce-123'", 
    30         "returned_csp": "script-src 'nonce-abc'", 
     28      { "name": "Iframe with more restricting CSP should load.",
     29        "required_csp": "script-src 'nonce-abc' 'nonce-123'",
     30        "returned_csp": "script-src 'nonce-abc'",
    3131        "expected": IframeLoad.EXPECT_LOAD },
    32       { "name": "Iframe with less restricting CSP should be blocked.", 
    33         "required_csp": "style-src 'none'; script-src 'none'", 
    34         "returned_csp": "style-src 'none'; script-src 'self' 'nonce-abc'", 
     32      { "name": "Iframe with less restricting CSP should be blocked.",
     33        "required_csp": "style-src 'none'; script-src 'none'",
     34        "returned_csp": "style-src 'none'; script-src 'self' 'nonce-abc'",
    3535        "expected": IframeLoad.EXPECT_BLOCK },
    36       { "name": "Iframe with a different CSP should be blocked.", 
    37         "required_csp": "script-src 'nonce-abc' 'nonce-123'", 
    38         "returned_csp": "style-src 'none'", 
     36      { "name": "Iframe with a different CSP should be blocked.",
     37        "required_csp": "script-src 'nonce-abc' 'nonce-123'",
     38        "returned_csp": "style-src 'none'",
    3939        "expected": IframeLoad.EXPECT_BLOCK },
    40       { "name": "Iframe with a matching and more restrictive ports should load.", 
    41         "required_csp": "frame-src http://c.com:443 http://b.com", 
    42         "returned_csp": "frame-src http://b.com:80 http://c.com:443", 
     40      { "name": "Iframe with a matching and more restrictive ports should load.",
     41        "required_csp": "frame-src http://c.com:443 http://b.com",
     42        "returned_csp": "frame-src http://b.com:80 http://c.com:443",
    4343        "expected": IframeLoad.EXPECT_LOAD },
    44       { "name": "Iframe should load even if the ports are different but are default for the protocols.",
    45         "required_csp": "frame-src http://b.com:80",
    46         "returned_csp": "child-src https://b.com:443",
     44      { "name": "Host wildcard *.a.com does not match a.com",
     45        "required_csp": "frame-src http://*.a.com",
     46        "returned_csp": "frame-src http://a.com",
     47        "expected": IframeLoad.EXPECT_BLOCK },
     48      { "name": "Host intersection with wildcards is computed correctly.",
     49        "required_csp": "frame-sr 'none'",
     50        "returned_csp": "frame-src http://a.com",
     51        "returned_csp_2": "frame-src http://*.a.com",
    4752        "expected": IframeLoad.EXPECT_LOAD },
     53      { "name": "Iframe should load even if the ports are different but are default for the protocols.",
     54        "required_csp": "frame-src http://b.com:80",
     55        "returned_csp": "child-src https://b.com:443",
     56        "expected": IframeLoad.EXPECT_LOAD },
     57      { "name": "Iframe should block if intersection allows sources which are not in required_csp.",
     58        "required_csp": "style-src http://*.example.com:*",
     59        "returned_csp": "style-src http://*.com:*",
     60        "returned_csp_2": "style-src http://*.com http://*.example.com:*",
     61        "expected": IframeLoad.EXPECT_BLOCK },
     62      { "name": "Iframe should block if intersection allows sources which are not in required_csp (other ordering).",
     63        "required_csp": "style-src http://*.example.com:*",
     64        "returned_csp": "style-src http://*.com:*",
     65        "returned_csp_2": "style-src http://*.example.com:* http://*.com",
     66        "expected": IframeLoad.EXPECT_BLOCK },
     67      { "name": "Iframe should load if intersection allows only sources which are in required_csp.",
     68        "required_csp": "style-src http://*.example.com",
     69        "returned_csp": "style-src http://*.example.com:*",
     70        "returned_csp_2": "style-src http://*.com",
     71        "expected": IframeLoad.EXPECT_LOAD },
     72      { "name": "Removed plugin-types directive should be ignored.",
     73        "required_csp": "plugin-types application/pdf",
     74        "returned_csp": null,
     75        "expected": IframeLoad.EXPECT_LOAD },
     76      { "name": "Removed plugin-types directive should be ignored 2.",
     77        "required_csp": "plugin-types application/pdf application/x-java-applet",
     78        "returned_csp": "plugin-types application/pdf",
     79        "expected": IframeLoad.EXPECT_LOAD },
     80      { "name": "Removed plugin-types directive should be ignored 3.",
     81        "required_csp": "style-src 'none'; plugin-types application/pdf",
     82        "returned_csp": null,
     83        "expected": IframeLoad.EXPECT_BLOCK },
    4884    ];
    4985
     
    5187      async_test(t =>  {
    5288        var url = generateUrlWithPolicies(Host.CROSS_ORIGIN, test.returned_csp);
     89        if (test.returned_csp_2)
     90          url.searchParams.append("policy2", test.returned_csp_2);
    5391        assert_iframe_with_csp(t, url, test.required_csp, test.expected, test.name, null);
    5492      }, test.name);
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-hashes.html

    r246330 r279838  
    1010  <script>
    1111    var tests = [
    12       { "name": "'sha256-abc123' is properly subsumed.", 
    13         "required_csp": "style-src 'sha256-abc123'", 
     12      { "name": "'sha256-abc123' is properly subsumed.",
     13        "required_csp": "style-src 'sha256-abc123'",
    1414        "returned_csp_1": "style-src 'sha256-abc123'",
    1515        "expected": IframeLoad.EXPECT_LOAD },
    16       { "name": "Returned should not include hashes not present in required csp.", 
    17         "required_csp": "style-src http://example.com", 
     16      { "name": "Returned should not include hashes not present in required csp.",
     17        "required_csp": "style-src http://example.com",
    1818        "returned_csp_1": "style-src 'sha256-abc123'",
    1919        "expected": IframeLoad.EXPECT_BLOCK },
    20       { "name": "'sha256-abc123' is properly subsumed with other sources.", 
    21         "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-hashed-attributes' 'strict-dynamic' 'sha256-abc123'", 
     20      { "name": "'sha256-abc123' is properly subsumed with other sources.",
     21        "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-hashed-attributes' 'strict-dynamic' 'sha256-abc123'",
    2222        "returned_csp_1": "style-src http://example1.com/foo/bar.html 'sha256-abc123'",
    2323        "expected": IframeLoad.EXPECT_LOAD },
    24       { "name": "Hashes do not have to be present in returned csp.", 
    25         "required_csp": "style-src http://example1.com/foo/ 'self' 'sha256-abc123'", 
     24      { "name": "Hashes do not have to be present in returned csp.",
     25        "required_csp": "style-src http://example1.com/foo/ 'self' 'sha256-abc123'",
    2626        "returned_csp_1": "style-src http://example1.com/foo/",
    2727        "expected": IframeLoad.EXPECT_LOAD },
    28       { "name": "Hashes do not have to be present in returned csp but must not allow all inline behavior.", 
    29         "required_csp": "style-src http://example1.com/foo/ 'self' 'sha256-abc123'", 
     28      { "name": "Hashes do not have to be present in returned csp but must not allow all inline behavior.",
     29        "required_csp": "style-src http://example1.com/foo/ 'self' 'sha256-abc123'",
    3030        "returned_csp_1": "style-src http://example1.com/foo/ 'unsafe-inline'",
    3131        "expected": IframeLoad.EXPECT_BLOCK },
    32       { "name": "Other expressions have to be subsumed.", 
    33         "required_csp": "style-src http://example1.com/foo/ 'self' 'sha256-abc123'", 
     32      { "name": "Other expressions have to be subsumed.",
     33        "required_csp": "style-src http://example1.com/foo/ 'self' 'sha256-abc123'",
    3434        "returned_csp_1": "style-src http://example1.com/foo/ 'unsafe-eval' 'sha256-abc123'",
    3535        "expected": IframeLoad.EXPECT_BLOCK },
    36       { "name": "Other expressions have to be subsumed but 'unsafe-inline' gets ignored.", 
    37         "required_csp": "style-src http://example1.com/foo/ 'self' 'sha256-abc123'", 
     36      { "name": "Other expressions have to be subsumed but 'unsafe-inline' gets ignored.",
     37        "required_csp": "style-src http://example1.com/foo/ 'self' 'sha256-abc123'",
    3838        "returned_csp_1": "style-src http://example1.com/foo/ 'unsafe-inline' 'sha256-abc123'",
    3939        "expected": IframeLoad.EXPECT_LOAD },
    40       { "name": "Effective policy is properly found.", 
    41         "required_csp": "style-src http://example1.com/foo/ 'self'  'sha256-abc123'", 
     40      { "name": "Effective policy is properly found.",
     41        "required_csp": "style-src http://example1.com/foo/ 'self'  'sha256-abc123'",
    4242        "returned_csp_1": "style-src http://example1.com/foo/ 'unsafe-hashed-attributes' 'sha256-abc123'",
    4343        "returned_csp_2": "style-src http://example1.com/foo/ 'self' 'sha256-abc123'",
    4444        "expected": IframeLoad.EXPECT_LOAD },
    45       { "name": "Required csp must allow 'sha256-abc123'.", 
    46         "required_csp": "style-src http://example1.com/foo/ 'self'", 
     45      { "name": "Required csp must allow 'sha256-abc123'.",
     46        "required_csp": "style-src http://example1.com/foo/ 'self'",
    4747        "returned_csp_1": "style-src http://example1.com/foo/ 'self'  'sha256-abc123'",
    4848        "expected": IframeLoad.EXPECT_BLOCK },
    49       { "name": "Effective policy is properly found where 'sha256-abc123' is not subsumed.", 
    50         "required_csp": "style-src http://example1.com/foo/ 'self'", 
     49      { "name": "Effective policy is properly found where 'sha256-abc123' is not subsumed.",
     50        "required_csp": "style-src http://example1.com/foo/ 'self'",
    5151        "returned_csp_1": "style-src 'unsafe-hashed-attributes' 'sha256-abc123'",
    5252        "returned_csp_2": "style-src 'sha256-abc123' 'unsafe-inline'",
    5353        "expected": IframeLoad.EXPECT_BLOCK },
    54       { "name": "'sha256-abc123' is not subsumed by 'sha256-abc456'.", 
    55         "required_csp": "style-src http://example1.com/foo/ 'self' 'sha256-abc456'", 
     54      { "name": "'sha256-abc123' is not subsumed by 'sha256-abc456'.",
     55        "required_csp": "style-src http://example1.com/foo/ 'self' 'sha256-abc456'",
    5656        "returned_csp_1": "style-src 'unsafe-hashed-attributes' 'sha256-abc123'",
    5757        "returned_csp_2": "style-src 'sha256-abc123' 'unsafe-inline'",
    5858        "expected": IframeLoad.EXPECT_BLOCK },
    59       { "name": "Effective policy now does not allow 'sha256-abc123'.", 
    60         "required_csp": "style-src http://example1.com/foo/ 'self' 'sha256-abc456'", 
     59      { "name": "Effective policy now does not allow 'sha256-abc123'.",
     60        "required_csp": "style-src http://example1.com/foo/ 'self' 'sha256-abc456'",
    6161        "returned_csp_1": "style-src 'unsafe-hashed-attributes' 'sha256-abc123' 'sha256-abc456'",
    6262        "returned_csp_2": "style-src 'sha256-abc456' 'unsafe-inline'",
    6363        "expected": IframeLoad.EXPECT_LOAD },
    64       { "name": "Effective policy is properly found where 'sha256-abc123' is not part of it.", 
    65         "required_csp": "style-src http://example1.com/foo/ 'self'", 
     64      { "name": "Effective policy is properly found where 'sha256-abc123' is not part of it.",
     65        "required_csp": "style-src http://example1.com/foo/ 'self'",
    6666        "returned_csp_1": "style-src 'unsafe-hashed-attributes' 'self'",
    6767        "returned_csp_2": "style-src 'sha256-abc123' 'self'",
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-host_sources-hosts.html

    r246330 r279838  
    1010  <script>
    1111    var tests = [
    12       { "name": "Host must match.", 
    13         "required_csp": "img-src http://c.com", 
     12      { "name": "Host must match.",
     13        "required_csp": "img-src http://c.com",
    1414        "returned_csp": "img-src http://b.com",
    1515        "expected": IframeLoad.EXPECT_BLOCK },
    16       { "name": "Hosts without wildcards must match.", 
    17         "required_csp": "img-src http://c.com:* http://inner.b.com", 
     16      { "name": "Hosts without wildcards must match.",
     17        "required_csp": "img-src http://c.com:* http://inner.b.com",
    1818        "returned_csp": "img-src http://b.com",
    1919        "expected": IframeLoad.EXPECT_BLOCK },
    20       { "name": "More specific subdomain should not match.", 
    21         "required_csp": "img-src http://c.com:* http://b.com", 
     20      { "name": "More specific subdomain should not match.",
     21        "required_csp": "img-src http://c.com:* http://b.com",
    2222        "returned_csp": "img-src http://inner.b.com",
    2323        "expected": IframeLoad.EXPECT_BLOCK },
    24       { "name": "Specified host should not match a wildcard host.", 
    25         "required_csp": "img-src http://c.com:* http://inner.b.com", 
     24      { "name": "Specified host should not match a wildcard host.",
     25        "required_csp": "img-src http://c.com:* http://inner.b.com",
    2626        "returned_csp": "img-src http://*.b.com",
    2727        "expected": IframeLoad.EXPECT_BLOCK },
    28       { "name": "A wildcard host should match a more specific host.", 
    29         "required_csp": "img-src http://c.com:* http://*.b.com", 
     28      { "name": "A wildcard host should match a more specific host.",
     29        "required_csp": "img-src http://c.com:* http://*.b.com",
    3030        "returned_csp": "img-src https://inner.b.com",
    3131        "expected": IframeLoad.EXPECT_LOAD },
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-host_sources-paths.html

    r246330 r279838  
    1010  <script>
    1111    var tests = [
    12       { "name": "Returned CSP must specify a path.", 
    13         "required_csp": "img-src http://c.com:* http://b.com/example.html", 
    14         "returned_csp": "img-src http://b.com", 
     12      { "name": "Returned CSP must specify a path.",
     13        "required_csp": "img-src http://c.com:* http://b.com/example.html",
     14        "returned_csp": "img-src http://b.com",
    1515        "expected": IframeLoad.EXPECT_BLOCK },
    16       { "name": "Returned CSP has a more specific path.", 
    17         "required_csp": "img-src http://c.com:* http://b.com", 
    18         "returned_csp": "img-src http://b.com/example.html", 
     16      { "name": "Returned CSP has a more specific path.",
     17        "required_csp": "img-src http://c.com:* http://b.com",
     18        "returned_csp": "img-src http://b.com/example.html",
    1919        "expected": IframeLoad.EXPECT_LOAD },
    20       { "name": "Matching paths.", 
     20      { "name": "Matching paths.",
    2121        "required_csp": "img-src http://c.com:* http://b.com/example.html",
    2222        "returned_csp": "img-src http://b.com/example.html",
    2323        "expected": IframeLoad.EXPECT_LOAD },
    24       { "name": "Empty path is not subsumed by specified paths.", 
     24      { "name": "Empty path is not subsumed by specified paths.",
    2525        "required_csp": "img-src http://b.com/page1.html http://b.com/page2.html http://b.com/page3.html",
    2626        "returned_csp": "img-src http://b.com/",
    2727        "expected": IframeLoad.EXPECT_BLOCK },
    28       { "name": "All specific paths match except the order.", 
    29         "required_csp": "img-src http://b.com/page1.html http://b.com/page2.html http://b.com/page3.html", 
    30         "returned_csp": "img-src http://b.com/page2.html http://b.com/page3.html http://b.com/page1.html", 
     28      { "name": "All specific paths match except the order.",
     29        "required_csp": "img-src http://b.com/page1.html http://b.com/page2.html http://b.com/page3.html",
     30        "returned_csp": "img-src http://b.com/page2.html http://b.com/page3.html http://b.com/page1.html",
    3131        "expected": IframeLoad.EXPECT_LOAD },
    32       { "name": "Returned CSP allows only one path.", 
    33         "required_csp": "img-src http://b.com/page1.html http://b.com/page2.html http://b.com/page3.html", 
    34         "returned_csp": "img-src http://b.com/page2.html", 
     32      { "name": "Returned CSP allows only one path.",
     33        "required_csp": "img-src http://b.com/page1.html http://b.com/page2.html http://b.com/page3.html",
     34        "returned_csp": "img-src http://b.com/page2.html",
    3535        "expected": IframeLoad.EXPECT_LOAD },
    36       { "name": "`/` path should be subsumed by an empty path.", 
    37         "required_csp": "img-src http://b.com", 
    38         "returned_csp": "img-src http://b.com/", 
     36      { "name": "`/` path should be subsumed by an empty path.",
     37        "required_csp": "img-src http://b.com",
     38        "returned_csp": "img-src http://b.com/",
    3939        "expected": IframeLoad.EXPECT_LOAD },
    40       { "name": "Unspecified path should be subsumed by `/`.", 
    41         "required_csp": "img-src http://b.com/", 
    42         "returned_csp": "img-src http://b.com", 
     40      { "name": "Unspecified path should be subsumed by `/`.",
     41        "required_csp": "img-src http://b.com/",
     42        "returned_csp": "img-src http://b.com",
    4343        "expected": IframeLoad.EXPECT_LOAD },
    44       { "name": "That should not be true when required csp specifies a specific page.", 
    45         "required_csp": "img-src http://b.com/path.html", 
    46         "returned_csp": "img-src http://b.com", 
     44      { "name": "That should not be true when required csp specifies a specific page.",
     45        "required_csp": "img-src http://b.com/path.html",
     46        "returned_csp": "img-src http://b.com",
    4747        "expected": IframeLoad.EXPECT_BLOCK },
    4848    ];
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-host_sources-ports.html

    r246330 r279838  
    1010  <script>
    1111    var tests = [
    12       { "name": "Specified ports must match.", 
    13         "required_csp": "img-src http://c.com:* http://b.com:80", 
    14         "returned_csp": "img-src http://b.com:36", 
     12      { "name": "Specified ports must match.",
     13        "required_csp": "img-src http://c.com:* http://b.com:80",
     14        "returned_csp": "img-src http://b.com:36",
    1515        "expected": IframeLoad.EXPECT_BLOCK },
    16       { "name": "Returned CSP should be subsumed even if the port is not specified but is a default port for a scheme.", 
    17         "required_csp": "img-src http://c.com:* http://b.com:80", 
    18         "returned_csp": "img-src http://b.com", 
     16      { "name": "Returned CSP should be subsumed even if the port is not specified but is a default port for a scheme.",
     17        "required_csp": "img-src http://c.com:* http://b.com:80",
     18        "returned_csp": "img-src http://b.com",
    1919        "expected": IframeLoad.EXPECT_LOAD },
    20       { "name": "Returned CSP should be subsumed even if the port is not specified but is a default port for a more secure scheme.", 
    21         "required_csp": "img-src http://c.com:* http://b.com:80", 
    22         "returned_csp": "img-src https://b.com", 
     20      { "name": "Returned CSP should be subsumed even if the port is not specified but is a default port for a more secure scheme.",
     21        "required_csp": "img-src http://c.com:* http://b.com:80",
     22        "returned_csp": "img-src https://b.com",
    2323        "expected": IframeLoad.EXPECT_LOAD },
    24       { "name": "The same should hold for `ws` case.", 
    25         "required_csp": "img-src http://c.com:* ws://b.com:80", 
    26         "returned_csp": "img-src wss://b.com", 
     24      { "name": "The same should hold for `ws` case.",
     25        "required_csp": "img-src http://c.com:* ws://b.com:80",
     26        "returned_csp": "img-src wss://b.com",
    2727        "expected": IframeLoad.EXPECT_LOAD },
    28       { "name": "Unspecified ports must match if schemes match.", 
    29         "required_csp": "img-src http://c.com:* http://b.com", 
    30         "returned_csp": "img-src https://b.com", 
     28      { "name": "Unspecified ports must match if schemes match.",
     29        "required_csp": "img-src http://c.com:* http://b.com",
     30        "returned_csp": "img-src https://b.com",
    3131        "expected": IframeLoad.EXPECT_LOAD },
    32       { "name": "Returned CSP should be subsumed if the port is specified.", 
    33         "required_csp": "img-src http://c.com:* http://b.com", 
    34         "returned_csp": "img-src http://b.com:80", 
     32      { "name": "Returned CSP should be subsumed if the port is specified.",
     33        "required_csp": "img-src http://c.com:* http://b.com",
     34        "returned_csp": "img-src http://b.com:80",
    3535        "expected": IframeLoad.EXPECT_LOAD },
    36       { "name": "Returned CSP should be subsumed if the port is specified but the scheme is more secure.", 
    37         "required_csp": "img-src http://c.com:* http://b.com", 
    38         "returned_csp": "img-src https://b.com:443", 
     36      { "name": "Returned CSP should be subsumed if the port is specified but the scheme is more secure.",
     37        "required_csp": "img-src http://c.com:* http://b.com",
     38        "returned_csp": "img-src https://b.com:443",
    3939        "expected": IframeLoad.EXPECT_LOAD },
    40       { "name": "Returned CSP should be subsumed if the port is specified but is not default for a more secure scheme.", 
    41         "required_csp": "img-src http://c.com:* http://b.com", 
    42         "returned_csp": "img-src https://b.com:36", 
     40      { "name": "Returned CSP should be subsumed if the port is specified but is not default for a more secure scheme.",
     41        "required_csp": "img-src http://c.com:* http://b.com",
     42        "returned_csp": "img-src https://b.com:36",
    4343        "expected": IframeLoad.EXPECT_BLOCK },
    44       { "name": "Returned CSP should be subsumed if the ports match but schemes are not identical.", 
    45         "required_csp": "img-src http://c.com:* http://b.com:36", 
    46         "returned_csp": "img-src https://b.com:36", 
     44      { "name": "Returned CSP should be subsumed if the ports match but schemes are not identical.",
     45        "required_csp": "img-src http://c.com:* http://b.com:36",
     46        "returned_csp": "img-src https://b.com:36",
    4747        "expected": IframeLoad.EXPECT_LOAD },
    48       { "name": "Returned CSP should be subsumed if the ports match but schemes are not identical for `ws`.", 
    49         "required_csp": "img-src http://c.com:* ws://b.com:36", 
    50         "returned_csp": "img-src wss://b.com:36", 
     48      { "name": "Returned CSP should be subsumed if the ports match but schemes are not identical for `ws`.",
     49        "required_csp": "img-src http://c.com:* ws://b.com:36",
     50        "returned_csp": "img-src wss://b.com:36",
    5151        "expected": IframeLoad.EXPECT_LOAD },
    52       { "name": "Wildcard port should match unspecified port.", 
    53         "required_csp": "img-src http://c.com:* ws://b.com:*", 
    54         "returned_csp": "img-src wss://b.com", 
     52      { "name": "Wildcard port should match unspecified port.",
     53        "required_csp": "img-src http://c.com:* ws://b.com:*",
     54        "returned_csp": "img-src wss://b.com",
    5555        "expected": IframeLoad.EXPECT_LOAD },
    56       { "name": "Wildcard port should match any specific port.", 
    57         "required_csp": "img-src http://c.com:* ws://b.com:*", 
    58         "returned_csp": "img-src wss://b.com:36", 
     56      { "name": "Wildcard port should match any specific port.",
     57        "required_csp": "img-src http://c.com:* ws://b.com:*",
     58        "returned_csp": "img-src wss://b.com:36",
    5959        "expected": IframeLoad.EXPECT_LOAD },
    60       { "name": "Wildcard port should match a wildcard.", 
    61         "required_csp": "img-src http://c.com:* ws://b.com:*", 
    62         "returned_csp": "img-src wss://b.com:*", 
     60      { "name": "Wildcard port should match a wildcard.",
     61        "required_csp": "img-src http://c.com:* ws://b.com:*",
     62        "returned_csp": "img-src wss://b.com:*",
    6363        "expected": IframeLoad.EXPECT_LOAD },
    64       { "name": "Wildcard port should not be subsumed by a default port.", 
    65         "required_csp": "img-src http://c.com:* ws://b.com", 
    66         "returned_csp": "img-src ws://b.com:*", 
     64      { "name": "Wildcard port should not be subsumed by a default port.",
     65        "required_csp": "img-src http://c.com:* ws://b.com",
     66        "returned_csp": "img-src ws://b.com:*",
    6767        "expected": IframeLoad.EXPECT_BLOCK },
    68       { "name": "Wildcard port should not be subsumed by a spcified port.", 
    69         "required_csp": "img-src http://c.com:* ws://b.com:80", 
    70         "returned_csp": "img-src ws://b.com:*", 
     68      { "name": "Wildcard port should not be subsumed by a spcified port.",
     69        "required_csp": "img-src http://c.com:* ws://b.com:80",
     70        "returned_csp": "img-src ws://b.com:*",
    7171        "expected": IframeLoad.EXPECT_BLOCK },
    7272    ];
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-host_sources-protocols.html

    r246330 r279838  
    1010  <script>
    1111    var tests = [
    12       { "name": "`https` is more restrictive than `http`.", 
    13         "required_csp": "img-src http://c.com:* https://b.com", 
     12      { "name": "`https` is more restrictive than `http`.",
     13        "required_csp": "img-src http://c.com:* https://b.com",
    1414        "returned_csp": "img-src http://b.com",
    1515        "expected": IframeLoad.EXPECT_BLOCK },
    16       { "name": "The reverse allows iframe be to be loaded.", 
    17         "required_csp": "img-src http://c.com:* http://b.com", 
     16      { "name": "The reverse allows iframe be to be loaded.",
     17        "required_csp": "img-src http://c.com:* http://b.com",
    1818        "returned_csp": "img-src https://b.com",
    1919        "expected": IframeLoad.EXPECT_LOAD },
    20       { "name": "Matching `https` protocols.", 
    21         "required_csp": "img-src http://c.com:* https://b.com", 
    22         "returned_csp": "img-src https://b.com", 
     20      { "name": "Matching `https` protocols.",
     21        "required_csp": "img-src http://c.com:* https://b.com",
     22        "returned_csp": "img-src https://b.com",
    2323        "expected": IframeLoad.EXPECT_LOAD },
    24       { "name": "`http:` should subsume all host source expressions with this protocol.", 
    25         "required_csp": "img-src http:", 
    26         "returned_csp": "img-src http://c.com:* https://b.com http://c.com", 
     24      { "name": "`http:` should subsume all host source expressions with this protocol.",
     25        "required_csp": "img-src http:",
     26        "returned_csp": "img-src http://c.com:* https://b.com http://c.com",
    2727        "expected": IframeLoad.EXPECT_LOAD },
    28       { "name": "`http:` should subsume all host source expressions with `https:`.", 
    29         "required_csp": "img-src http:", 
    30         "returned_csp": "img-src https://c.com:* https://b.com http://c.com", 
     28      { "name": "`http:` should subsume all host source expressions with `https:`.",
     29        "required_csp": "img-src http:",
     30        "returned_csp": "img-src https://c.com:* https://b.com http://c.com",
    3131        "expected": IframeLoad.EXPECT_LOAD },
    32       { "name": "`http:` does not subsume other protocols.", 
    33         "required_csp": "img-src http:", 
    34         "returned_csp": "img-src https://c.com:* wss://b.com http://c.com", 
     32      { "name": "`http:` does not subsume other protocols.",
     33        "required_csp": "img-src http:",
     34        "returned_csp": "img-src https://c.com:* wss://b.com http://c.com",
    3535        "expected": IframeLoad.EXPECT_BLOCK },
    36       { "name": "If scheme source is present in returned csp, it must be specified in required csp too.", 
    37         "required_csp": "img-src https://c.com:* wss://b.com http://c.com", 
    38         "returned_csp": "img-src http:", 
     36      { "name": "If scheme source is present in returned csp, it must be specified in required csp too.",
     37        "required_csp": "img-src https://c.com:* wss://b.com http://c.com",
     38        "returned_csp": "img-src http:",
    3939        "expected": IframeLoad.EXPECT_BLOCK },
    40       { "name": "`http:` subsumes other `http:` source expression.", 
    41         "required_csp": "img-src http:", 
    42         "returned_csp": "img-src http: https://c.com:* https://b.com http://c.com", 
     40      { "name": "`http:` subsumes other `http:` source expression.",
     41        "required_csp": "img-src http:",
     42        "returned_csp": "img-src http: https://c.com:* https://b.com http://c.com",
    4343        "expected": IframeLoad.EXPECT_LOAD },
    44       { "name": "`http:` subsumes other `https:` source expression and expressions with `http:`.", 
    45         "required_csp": "img-src http:", 
    46         "returned_csp": "img-src https: https://c.com:* http://b.com", 
     44      { "name": "`http:` subsumes other `https:` source expression and expressions with `http:`.",
     45        "required_csp": "img-src http:",
     46        "returned_csp": "img-src https: https://c.com:* http://b.com",
    4747        "expected": IframeLoad.EXPECT_LOAD },
    48       { "name": "All scheme sources must be subsumed.", 
    49         "required_csp": "img-src http: wss:", 
    50         "returned_csp": "img-src https: ws:", 
     48      { "name": "All scheme sources must be subsumed.",
     49        "required_csp": "img-src http: wss:",
     50        "returned_csp": "img-src https: ws:",
    5151        "expected": IframeLoad.EXPECT_BLOCK },
    52       { "name": "All scheme sources are subsumed by their stronger variants.", 
    53         "required_csp": "img-src http: wss:", 
    54         "returned_csp": "img-src https: wss:", 
     52      { "name": "All scheme sources are subsumed by their stronger variants.",
     53        "required_csp": "img-src http: wss:",
     54        "returned_csp": "img-src https: wss:",
    5555        "expected": IframeLoad.EXPECT_LOAD },
    5656    ];
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-none.html

    r246330 r279838  
    1010  <script>
    1111    var tests = [
    12       { "name": "Empty required csp subsumes empty list of returned policies.", 
    13         "required_csp": "", 
     12      { "name": "Empty required csp subsumes empty list of returned policies.",
     13        "required_csp": "",
    1414        "returned_csp_1": "",
    1515        "returned_csp_2": null,
    1616        "expected": IframeLoad.EXPECT_LOAD },
    17       { "name": "Empty required csp subsumes any list of policies.", 
    18         "required_csp": "", 
     17      { "name": "Empty required csp subsumes any list of policies.",
     18        "required_csp": "",
    1919        "returned_csp_1": "img-src http://example.com",
    2020        "returned_csp_2": null,
    2121        "expected": IframeLoad.EXPECT_LOAD },
    22       { "name": "Empty required csp subsumes a policy with `none`.", 
    23         "required_csp": "", 
     22      { "name": "Empty required csp subsumes a policy with `none`.",
     23        "required_csp": "",
    2424        "returned_csp_1": "img-src 'none'",
    2525        "returned_csp_2": null,
    2626        "expected": IframeLoad.EXPECT_LOAD },
    27       { "name": "Required policy that allows `none` does not subsume empty list of policies.", 
    28         "required_csp": "img-src ", 
     27      { "name": "Required policy that allows `none` does not subsume empty list of policies.",
     28        "required_csp": "img-src ",
    2929        "returned_csp_1": "",
    3030        "returned_csp_2": null,
    3131        "expected": IframeLoad.EXPECT_BLOCK },
    32       { "name": "Required csp with effective `none` does not subsume a host source expression.", 
    33         "required_csp": "img-src ", 
     32      { "name": "Required csp with effective `none` does not subsume a host source expression.",
     33        "required_csp": "img-src ",
    3434        "returned_csp_1": "img-src http://example.com",
    3535        "returned_csp_2": null,
    3636        "expected": IframeLoad.EXPECT_BLOCK },
    37       { "name": "Required csp with `none` does not subsume a host source expression.", 
    38         "required_csp": "img-src 'none'", 
     37      { "name": "Required csp with `none` does not subsume a host source expression.",
     38        "required_csp": "img-src 'none'",
    3939        "returned_csp_1": "img-src http://example.com",
    4040        "returned_csp_2": null,
    4141        "expected": IframeLoad.EXPECT_BLOCK },
    42       { "name": "Required csp with effective `none` does not subsume `none` of another directive.", 
    43         "required_csp": "img-src ", 
     42      { "name": "Required csp with effective `none` does not subsume `none` of another directive.",
     43        "required_csp": "img-src ",
    4444        "returned_csp_1": "frame-src 'none'",
    4545        "returned_csp_2": null,
    4646        "expected": IframeLoad.EXPECT_BLOCK },
    47       { "name": "Required csp with `none` does not subsume `none` of another directive.", 
    48         "required_csp": "img-src 'none'", 
     47      { "name": "Required csp with `none` does not subsume `none` of another directive.",
     48        "required_csp": "img-src 'none'",
    4949        "returned_csp_1": "frame-src 'none'",
    5050        "returned_csp_2": null,
    5151        "expected": IframeLoad.EXPECT_BLOCK },
    52       { "name": "Required csp with `none` does not subsume `none` of different directives.", 
    53         "required_csp": "img-src ", 
     52      { "name": "Required csp with `none` does not subsume `none` of different directives.",
     53        "required_csp": "img-src ",
    5454        "returned_csp_1": "img-src http://*.one.com",
    5555        "returned_csp_2": "frame-src https://two.com",
    5656        "expected": IframeLoad.EXPECT_BLOCK },
    57       { "name": "Required csp with `none` subsumes effective list of `none`.", 
    58         "required_csp": "img-src ", 
     57      { "name": "Required csp with `none` subsumes effective list of `none`.",
     58        "required_csp": "img-src ",
    5959        "returned_csp_1": "img-src http://*.one.com",
    6060        "returned_csp_2": "img-src https://two.com",
    6161        "expected": IframeLoad.EXPECT_LOAD },
    62       { "name": "Required csp with `none` subsumes effective list of `none` despite other keywords.", 
    63         "required_csp": "img-src 'none'", 
     62      { "name": "Required csp with `none` subsumes effective list of `none` despite other keywords.",
     63        "required_csp": "img-src 'none'",
    6464        "returned_csp_1": "img-src http://*.one.com",
    6565        "returned_csp_2": "img-src 'self'",
    6666        "expected": IframeLoad.EXPECT_LOAD },
    67       { "name": "Source list with exprssions other than `none` make `none` ineffective.", 
    68         "required_csp": "img-src http://example.com 'none'", 
     67      { "name": "Source list with exprssions other than `none` make `none` ineffective.",
     68        "required_csp": "img-src http://example.com 'none'",
    6969        "returned_csp_1": "img-src http://example.com",
    7070        "returned_csp_2": null,
    7171        "expected": IframeLoad.EXPECT_LOAD },
    72       { "name": "Returned csp with `none` is subsumed by any required csp.", 
    73         "required_csp": "img-src http://example.com", 
     72      { "name": "Returned csp with `none` is subsumed by any required csp.",
     73        "required_csp": "img-src http://example.com",
    7474        "returned_csp_1": "img-src 'none'",
    7575        "returned_csp_2": null,
    7676        "expected": IframeLoad.EXPECT_LOAD },
    77       { "name": "Returned csp with effective `none` is subsumed by any required csp.", 
    78         "required_csp": "img-src http://example.com", 
     77      { "name": "Returned csp with effective `none` is subsumed by any required csp.",
     78        "required_csp": "img-src http://example.com",
    7979        "returned_csp_1": "img-src http://example.com",
    8080        "returned_csp_2": "img-src http://non-example.com",
    8181        "expected": IframeLoad.EXPECT_LOAD },
    82       { "name": "Both required and returned csp are `none`.", 
    83         "required_csp": "img-src 'none'", 
     82      { "name": "Both required and returned csp are `none`.",
     83        "required_csp": "img-src 'none'",
    8484        "returned_csp_1": "img-src 'none'",
    8585        "returned_csp_2": "img-src http://non-example.com",
    8686        "expected": IframeLoad.EXPECT_LOAD },
    87       { "name": "Both required and returned csp are `none` for only one directive.", 
    88         "required_csp": "default-src 'none'", 
     87      { "name": "Both required and returned csp are `none` for only one directive.",
     88        "required_csp": "default-src 'none'",
    8989        "returned_csp_1": "img-src 'none'",
    9090        "returned_csp_2": "script-src 'unsafe-inline'",
    9191        "expected": IframeLoad.EXPECT_BLOCK },
    92       { "name": "Both required and returned csp are empty.", 
    93         "required_csp": "img-src ", 
     92      { "name": "Both required and returned csp are empty.",
     93        "required_csp": "img-src ",
    9494        "returned_csp_1": "img-src ",
    9595        "returned_csp_2": null,
    9696        "expected": IframeLoad.EXPECT_LOAD },
    97       { "name": "Both required and returned csp are effectively 'none'.", 
    98         "required_csp": "img-src ", 
     97      { "name": "Both required and returned csp are effectively 'none'.",
     98        "required_csp": "img-src ",
    9999        "returned_csp_1": "img-src http://a.com",
    100100        "returned_csp_2": "img-src http://b.com",
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-self.html

    r246330 r279838  
    1010  <script>
    1111    var tests = [
    12       { "name": "'self' keywords should match.", 
    13         "required_csp": "img-src 'self' http://b.com:*", 
     12      { "name": "'self' keywords should match.",
     13        "required_csp": "img-src 'self' http://b.com:*",
    1414        "returned_csp": "img-src 'self' http://b.com:*",
    1515        "expected": IframeLoad.EXPECT_LOAD },
    16       { "name": "Returned CSP does not have to specify 'self'.", 
    17         "required_csp": "img-src 'self' http://b.com:*", 
     16      { "name": "Returned CSP does not have to specify 'self'.",
     17        "required_csp": "img-src 'self' http://b.com:*",
    1818        "returned_csp": "img-src http://b.com:*",
    1919        "expected": IframeLoad.EXPECT_LOAD },
    20       { "name": "Returned CSP must not allow 'self' if required CSP does not.", 
    21         "required_csp": "img-src http://b.com:*", 
     20      { "name": "Returned CSP must not allow 'self' if required CSP does not.",
     21        "required_csp": "img-src http://b.com:*",
    2222        "returned_csp": "img-src 'self' http://b.com:*",
    2323        "expected": IframeLoad.EXPECT_BLOCK },
    24       { "name": "Returned 'self' should match to an origin's url.", 
    25         "required_csp": "img-src 'self' http://b.com:*", 
     24      { "name": "Returned 'self' should match to an origin's url.",
     25        "required_csp": "img-src 'self' http://b.com:*",
    2626        "returned_csp": "img-src " + getCrossOrigin(),
    2727        "expected": IframeLoad.EXPECT_LOAD },
    28       { "name": "Required 'self' should match to a origin's url.", 
    29         "required_csp": "img-src " +  getCrossOrigin() + " http://b.com:*", 
     28      { "name": "Required 'self' should match to a origin's url.",
     29        "required_csp": "img-src " +  getCrossOrigin() + " http://b.com:*",
    3030        "returned_csp": "img-src 'self'",
    3131        "expected": IframeLoad.EXPECT_LOAD },
    32       { "name": "Required 'self' should subsume a more secure version of origin's url.", 
    33         "required_csp": "img-src 'self' http://b.com:*", 
     32      { "name": "Required 'self' should subsume a more secure version of origin's url.",
     33        "required_csp": "img-src 'self' http://b.com:*",
    3434        "returned_csp": "img-src " + getSecureCrossOrigin(),
    3535        "expected": IframeLoad.EXPECT_LOAD },
    36       { "name": "Returned 'self' should not be subsumed by a more secure version of origin's url.", 
    37         "required_csp": "img-src " + getSecureCrossOrigin() + " http://b.com:*", 
     36      { "name": "Returned 'self' should not be subsumed by a more secure version of origin's url.",
     37        "required_csp": "img-src " + getSecureCrossOrigin() + " http://b.com:*",
    3838        "returned_csp": "img-src 'self'",
    3939        "expected": IframeLoad.EXPECT_BLOCK },
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-strict_dynamic.html

    r263605 r279838  
    1414      // support/echo-policy-multiple.py), otherwise the test might
    1515      // return false negatives.
    16       { "name": "'strict-dynamic' is ineffective for `style-src`.", 
    17         "required_csp": "style-src http://example1.com/foo/ 'self'", 
     16      { "name": "'strict-dynamic' is ineffective for `style-src`.",
     17        "required_csp": "style-src http://example1.com/foo/ 'self'",
    1818        "returned_csp_1": "style-src 'strict-dynamic' http://example1.com/foo/bar.html",
    1919        "expected": IframeLoad.EXPECT_LOAD },
    20       { "name": "'strict-dynamic' is ineffective for `img-src`.", 
    21         "required_csp": "img-src http://example1.com/foo/ 'self'", 
     20      { "name": "'strict-dynamic' is ineffective for `img-src`.",
     21        "required_csp": "img-src http://example1.com/foo/ 'self'",
    2222        "returned_csp_1": "img-src 'strict-dynamic' http://example1.com/foo/bar.html",
    2323        "expected": IframeLoad.EXPECT_LOAD },
    24       { "name": "'strict-dynamic' is ineffective for `frame-src`.", 
    25         "required_csp": "frame-src http://example1.com/foo/ 'self'", 
     24      { "name": "'strict-dynamic' is ineffective for `frame-src`.",
     25        "required_csp": "frame-src http://example1.com/foo/ 'self'",
    2626        "returned_csp_1": "frame-src 'strict-dynamic' http://example1.com/foo/bar.html",
    2727        "expected": IframeLoad.EXPECT_LOAD },
    28       { "name": "'strict-dynamic' is ineffective for `child-src`.", 
    29         "required_csp": "child-src http://example1.com/foo/ 'self'", 
     28      { "name": "'strict-dynamic' is ineffective for `child-src`.",
     29        "required_csp": "child-src http://example1.com/foo/ 'self'",
    3030        "returned_csp_1": "child-src 'strict-dynamic' http://example1.com/foo/bar.html",
    3131        "expected": IframeLoad.EXPECT_LOAD },
    32       { "name": "'strict-dynamic' is effective only for `script-src`.", 
    33         "required_csp": "script-src http://example1.com/foo/ 'self'", 
     32      { "name": "'strict-dynamic' is effective only for `script-src`.",
     33        "required_csp": "script-src http://example1.com/foo/ 'self'",
    3434        "returned_csp_1": "script-src 'strict-dynamic' http://example1.com/foo/bar.html 'nonce-abc'",
    3535        "expected": IframeLoad.EXPECT_BLOCK },
    3636      { "name": "'strict-dynamic' is properly handled for finding effective policy.",
    37         "required_csp": "script-src http://example1.com/foo/ 'self'", 
     37        "required_csp": "script-src http://example1.com/foo/ 'self'",
    3838        "returned_csp_1": "script-src 'strict-dynamic' http://example1.com/foo/bar.html 'nonce-abc'",
    3939        "returned_csp_2": "script-src 'strict-dynamic' 'nonce-abc'",
    4040        "expected": IframeLoad.EXPECT_BLOCK },
    41       { "name": "'strict-dynamic' makes host source expressions ineffective.", 
    42         "required_csp": "script-src 'strict-dynamic' 'nonce-abc'", 
     41      { "name": "'strict-dynamic' makes host source expressions ineffective.",
     42        "required_csp": "script-src 'strict-dynamic' 'nonce-abc'",
    4343        "returned_csp_1": "script-src http://example.com 'strict-dynamic' 'nonce-abc'",
    4444        "expected": IframeLoad.EXPECT_LOAD },
    45       { "name": "'strict-dynamic' makes scheme source expressions ineffective.", 
    46         "required_csp": "script-src 'strict-dynamic' 'nonce-abc'", 
     45      { "name": "'strict-dynamic' makes scheme source expressions ineffective.",
     46        "required_csp": "script-src 'strict-dynamic' 'nonce-abc'",
    4747        "returned_csp_1": "script-src http: 'strict-dynamic' 'nonce-abc'",
    4848        "expected": IframeLoad.EXPECT_LOAD },
    49       { "name": "'strict-dynamic' makes 'self' ineffective.", 
    50         "required_csp": "script-src 'strict-dynamic' 'nonce-abc'", 
     49      { "name": "'strict-dynamic' makes 'self' ineffective.",
     50        "required_csp": "script-src 'strict-dynamic' 'nonce-abc'",
    5151        "returned_csp_1": "script-src 'self' 'strict-dynamic' 'nonce-abc'",
    5252        "expected": IframeLoad.EXPECT_LOAD },
    53       { "name": "'strict-dynamic' makes 'unsafe-inline' ineffective.", 
    54         "required_csp": "script-src 'strict-dynamic' 'nonce-abc'", 
     53      { "name": "'strict-dynamic' makes 'unsafe-inline' ineffective.",
     54        "required_csp": "script-src 'strict-dynamic' 'nonce-abc'",
    5555        "returned_csp_1": "script-src 'unsafe-inline' 'strict-dynamic' 'nonce-abc'",
    5656        "expected": IframeLoad.EXPECT_LOAD },
    57       { "name": "'strict-dynamic' has to be allowed by required csp if it is present in returned csp.", 
    58         "required_csp": "script-src 'nonce-abc'", 
     57      { "name": "'strict-dynamic' has to be allowed by required csp if it is present in returned csp.",
     58        "required_csp": "script-src 'nonce-abc'",
    5959        "returned_csp_1": "script-src 'strict-dynamic' 'nonce-abc'",
    6060        "expected": IframeLoad.EXPECT_BLOCK },
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-unsafe_eval.html

    r246330 r279838  
    1010  <script>
    1111    var tests = [
    12       { "name": "'unsafe-eval' is properly subsumed.", 
    13         "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-hashed-attributes' 'strict-dynamic' 'unsafe-eval'", 
     12      { "name": "'unsafe-eval' is properly subsumed.",
     13        "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-hashed-attributes' 'strict-dynamic' 'unsafe-eval'",
    1414        "returned_csp_1": "style-src http://example1.com/foo/bar.html 'unsafe-eval'",
    1515        "expected": IframeLoad.EXPECT_LOAD },
    16       { "name": "No other keyword has the same effect as 'unsafe-eval'.", 
    17         "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-eval'", 
     16      { "name": "No other keyword has the same effect as 'unsafe-eval'.",
     17        "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-eval'",
    1818        "returned_csp_1": "style-src http://example1.com/foo/ 'unsafe-inline'",
    1919        "expected": IframeLoad.EXPECT_BLOCK },
    20       { "name": "Other expressions have to be subsumed.", 
    21         "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-eval'", 
     20      { "name": "Other expressions have to be subsumed.",
     21        "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-eval'",
    2222        "returned_csp_1": "style-src http://example1.com/foo/ 'unsafe-inline' 'unsafe-eval'",
    2323        "expected": IframeLoad.EXPECT_BLOCK },
    24       { "name": "Effective policy is properly found.", 
    25         "required_csp": "style-src http://example1.com/foo/ 'self'  'unsafe-eval'", 
     24      { "name": "Effective policy is properly found.",
     25        "required_csp": "style-src http://example1.com/foo/ 'self'  'unsafe-eval'",
    2626        "returned_csp_1": "style-src http://example1.com/foo/ 'unsafe-hashed-attributes' 'unsafe-eval'",
    2727        "returned_csp_2": "style-src http://example1.com/foo/ 'self' 'unsafe-eval'",
    2828        "expected": IframeLoad.EXPECT_LOAD },
    29       { "name": "Required csp must allow 'unsafe-eval'.", 
    30         "required_csp": "style-src http://example1.com/foo/ 'self'", 
     29      { "name": "Required csp must allow 'unsafe-eval'.",
     30        "required_csp": "style-src http://example1.com/foo/ 'self'",
    3131        "returned_csp_1": "style-src http://example1.com/foo/ 'self'  'unsafe-eval'",
    3232        "expected": IframeLoad.EXPECT_BLOCK },
    33       { "name": "Effective policy is properly found where 'unsafe-eval' is not subsumed.", 
    34         "required_csp": "style-src http://example1.com/foo/ 'self'", 
     33      { "name": "Effective policy is properly found where 'unsafe-eval' is not subsumed.",
     34        "required_csp": "style-src http://example1.com/foo/ 'self'",
    3535        "returned_csp_1": "style-src 'unsafe-hashed-attributes' 'unsafe-eval'",
    3636        "returned_csp_2": "style-src 'unsafe-eval' 'unsafe-inline'",
    3737        "expected": IframeLoad.EXPECT_BLOCK },
    38       { "name": "Effective policy is properly found where 'unsafe-eval' is not part of it.", 
    39         "required_csp": "style-src http://example1.com/foo/ 'self'", 
     38      { "name": "Effective policy is properly found where 'unsafe-eval' is not part of it.",
     39        "required_csp": "style-src http://example1.com/foo/ 'self'",
    4040        "returned_csp_1": "style-src 'unsafe-hashed-attributes' 'self'",
    4141        "returned_csp_2": "style-src 'unsafe-eval' 'self'",
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-unsafe_inline.html

    r263605 r279838  
    1010  <script>
    1111    var tests = [
    12       { "name": "'strict-dynamic' is ineffective for `style-src`.", 
    13         "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline' 'strict-dynamic'", 
     12      { "name": "'strict-dynamic' is ineffective for `style-src`.",
     13        "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline' 'strict-dynamic'",
    1414        "returned_csp_1": "style-src 'unsafe-inline' http://example1.com/foo/bar.html",
    1515        "returned_csp_2": null,
    1616        "expected": IframeLoad.EXPECT_LOAD },
    17       { "name": "'unsafe-inline' is properly subsumed in `style-src`.", 
    18         "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline'", 
     17      { "name": "'unsafe-inline' is properly subsumed in `style-src`.",
     18        "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline'",
    1919        "returned_csp_1": "style-src http://example1.com/foo/ 'unsafe-inline'",
    2020        "returned_csp_2": null,
    2121        "expected": IframeLoad.EXPECT_LOAD },
    22       { "name": "'unsafe-inline' is only ineffective if the effective returned csp has nonces in `style-src`.", 
    23         "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline'", 
     22      { "name": "'unsafe-inline' is only ineffective if the effective returned csp has nonces in `style-src`.",
     23        "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline'",
    2424        "returned_csp_1": "style-src 'unsafe-inline' 'nonce-yay'",
    2525        "returned_csp_2": "style-src 'unsafe-inline'",
    2626        "expected": IframeLoad.EXPECT_LOAD },
    27       { "name": "'unsafe-inline' is only ineffective if the effective returned csp has hashes in `style-src`.", 
    28         "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline'", 
     27      { "name": "'unsafe-inline' is only ineffective if the effective returned csp has hashes in `style-src`.",
     28        "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline'",
    2929        "returned_csp_1": "style-src 'unsafe-inline' 'sha256-abc123'",
    3030        "returned_csp_2": "style-src 'unsafe-inline'",
    3131        "expected": IframeLoad.EXPECT_LOAD },
    32       { "name": "Returned csp does not have to allow 'unsafe-inline' in `style-src` to be subsumed.", 
    33         "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline'", 
     32      { "name": "Returned csp does not have to allow 'unsafe-inline' in `style-src` to be subsumed.",
     33        "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline'",
    3434        "returned_csp_1": "style-src 'self'",
    3535        "returned_csp_2": null,
    3636        "expected": IframeLoad.EXPECT_LOAD },
    37       { "name": "'unsafe-inline' does not matter if returned csp is effectively `none`.", 
    38         "required_csp": "style-src 'unsafe-inline'", 
     37      { "name": "'unsafe-inline' does not matter if returned csp is effectively `none`.",
     38        "required_csp": "style-src 'unsafe-inline'",
    3939        "returned_csp_1": "style-src ",
    4040        "returned_csp_2": null,
    4141        "expected": IframeLoad.EXPECT_LOAD },
    42       { "name": "'unsafe-inline' is properly subsumed in `script-src`.", 
    43         "required_csp": "script-src http://example1.com/foo/ 'self' 'unsafe-inline'", 
     42      { "name": "'unsafe-inline' is properly subsumed in `script-src`.",
     43        "required_csp": "script-src http://example1.com/foo/ 'self' 'unsafe-inline'",
    4444        "returned_csp_1": "script-src http://example1.com/foo/ 'unsafe-inline'",
    4545        "returned_csp_2": null,
    4646        "expected": IframeLoad.EXPECT_LOAD },
    47       { "name": "Returned csp only loads 'unsafe-inline' scripts with 'nonce-abc'.", 
    48         "required_csp": "script-src http://example1.com/foo/ 'self' 'unsafe-inline'", 
     47      { "name": "Returned csp only loads 'unsafe-inline' scripts with 'nonce-abc'.",
     48        "required_csp": "script-src http://example1.com/foo/ 'self' 'unsafe-inline'",
    4949        "returned_csp_1": "script-src 'nonce-abc'",
    5050        "returned_csp_2": "script-src 'unsafe-inline'",
    5151        "expected": IframeLoad.EXPECT_LOAD },
    52       { "name": "'unsafe-inline' is ineffective when nonces are present.", 
    53         "required_csp": "script-src http://example1.com/foo/ 'self' 'unsafe-inline'", 
     52      { "name": "'unsafe-inline' is ineffective when nonces are present.",
     53        "required_csp": "script-src http://example1.com/foo/ 'self' 'unsafe-inline'",
    5454        "returned_csp_1": "script-src 'unsafe-inline' 'nonce-abc'",
    5555        "returned_csp_2": "script-src 'unsafe-inline'",
    5656        "expected": IframeLoad.EXPECT_LOAD },
    57       { "name": "'unsafe-inline' is only ineffective if the effective returned csp has hashes in `script-src`.", 
    58         "required_csp": "script-src http://example1.com/foo/ 'self' 'unsafe-inline'", 
     57      { "name": "'unsafe-inline' is only ineffective if the effective returned csp has hashes in `script-src`.",
     58        "required_csp": "script-src http://example1.com/foo/ 'self' 'unsafe-inline'",
    5959        "returned_csp_1": "script-src 'unsafe-inline' 'sha256-abc123' 'nonce-abc'",
    6060        "returned_csp_2": "script-src 'unsafe-inline'",
    6161        "expected": IframeLoad.EXPECT_LOAD },
    62       { "name": "Required csp allows `strict-dynamic`, but retuned csp does.", 
    63         "required_csp": "script-src http://example1.com/foo/ 'unsafe-inline' 'strict-dynamic'", 
     62      { "name": "Required csp allows `strict-dynamic`, but retuned csp does.",
     63        "required_csp": "script-src http://example1.com/foo/ 'unsafe-inline' 'strict-dynamic'",
    6464        "returned_csp_1": "script-src 'unsafe-inline' http://example1.com/foo/bar.html",
    6565        "returned_csp_2": null,
    6666        "expected": IframeLoad.EXPECT_BLOCK },
    67       { "name": "Required csp does not allow `unsafe-inline`, but retuned csp does.", 
    68         "required_csp": "style-src http://example1.com/foo/ 'self'", 
     67      { "name": "Required csp does not allow `unsafe-inline`, but retuned csp does.",
     68        "required_csp": "style-src http://example1.com/foo/ 'self'",
    6969        "returned_csp_1": "style-src 'unsafe-inline'",
    7070        "returned_csp_2": null,
    7171        "expected": IframeLoad.EXPECT_BLOCK },
    72       { "name": "Returned csp allows a nonce.", 
    73         "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline'", 
     72      { "name": "Returned csp allows a nonce.",
     73        "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline'",
    7474        "returned_csp_1": "style-src 'unsafe-inline' 'nonce-abc'",
    7575        "returned_csp_2": "style-src 'nonce-abc'",
    7676        "expected": IframeLoad.EXPECT_BLOCK },
    77       { "name": "Returned csp allows a hash.", 
    78         "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline'", 
     77      { "name": "Returned csp allows a hash.",
     78        "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline'",
    7979        "returned_csp_1": "style-src 'unsafe-inline' 'sha256-abc123'",
    8080        "returned_csp_2": "style-src 'sha256-abc123'",
    8181        "expected": IframeLoad.EXPECT_BLOCK },
    82       { "name": "Effective returned csp allows 'unsafe-inline'", 
    83         "required_csp": "style-src http://example1.com/foo/ 'self'", 
     82      { "name": "Effective returned csp allows 'unsafe-inline'",
     83        "required_csp": "style-src http://example1.com/foo/ 'self'",
    8484        "returned_csp_1": "style-src 'unsafe-inline' https://example.test/",
    8585        "returned_csp_2": "style-src 'unsafe-inline'",
    8686        "expected": IframeLoad.EXPECT_BLOCK },
    87       { "name": "Effective returned csp does not allow 'sha512-321cba' hash.", 
    88         "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline' 'sha512-321cba'", 
     87      { "name": "Effective returned csp does not allow 'sha512-321cba' hash.",
     88        "required_csp": "style-src http://example1.com/foo/ 'self' 'unsafe-inline' 'sha512-321cba'",
    8989        "returned_csp_1": "style-src http://example1.com/foo/ 'unsafe-inline' 'nonce-yay'",
    9090        "returned_csp_2": "style-src http://example1.com/foo/ 'unsafe-inline' 'sha512-321cba'",
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/support/echo-allow-csp-from.py

    r246330 r279838  
    11import json
    22def main(request, response):
    3     headers = [("Content-Type", "text/html")]
    4     if "allow_csp_from" in request.GET:
    5         headers.append(("Allow-CSP-From", request.GET["allow_csp_from"]))
    6     message = request.GET["id"]
    7     return headers, '''
     3    headers = [(b"Content-Type", b"text/html")]
     4    if b"allow_csp_from" in request.GET:
     5        headers.append((b"Allow-CSP-From", request.GET[b"allow_csp_from"]))
     6    message = request.GET[b"id"]
     7    return headers, b'''
    88<!DOCTYPE html>
    99<html>
     
    2222</head>
    2323<body>
     24    <script nonce="123">
     25        let img = document.createElement('img');
     26        img.src = "../../support/pass.png";
     27        img.onload = function() { window.top.postMessage("img loaded", '*'); }
     28        document.body.appendChild(img);
     29    </script>
    2430    <style>
    2531        body {
     
    2733        }
    2834    </style>
    29     <script nonce="abc"> 
     35    <script nonce="abc">
    3036        var response = {};
    3137        response["id"] = "%s";
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/support/echo-policy-multiple.py

    r246330 r279838  
    11def main(request, response):
    2     headers = [("Content-Type", "text/html")]
    3     if "policy" in request.GET:
    4         headers.append(("Content-Security-Policy", request.GET["policy"]))
    5     if "policy2" in request.GET:
    6         headers.append(("Content-Security-Policy", request.GET["policy2"]))
    7     if "policy3" in request.GET:
    8         headers.append(("Content-Security-Policy", request.GET["policy3"]))
    9     message = request.GET["id"]
    10     return headers, '''
     2    headers = [(b"Content-Type", b"text/html")]
     3    if b"policy" in request.GET:
     4        headers.append((b"Content-Security-Policy", request.GET[b"policy"]))
     5    if b"policy2" in request.GET:
     6        headers.append((b"Content-Security-Policy", request.GET[b"policy2"]))
     7    if b"policy3" in request.GET:
     8        headers.append((b"Content-Security-Policy", request.GET[b"policy3"]))
     9    message = request.GET[b"id"]
     10    return headers, b'''
    1111<!DOCTYPE html>
    1212<html>
     
    1515</head>
    1616<body>
    17     <script nonce="abc"> 
     17    <script nonce="abc">
    1818        var response = {};
    1919        response["id"] = "%s";
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/support/echo-required-csp.py

    r254133 r279838  
    11import json
     2
     3from wptserve.utils import isomorphic_decode
     4
    25def main(request, response):
    36    message = {}
    47
    5     header = request.headers.get("Test-Header-Injection");
    6     message['test_header_injection'] = header if header else None
     8    header = request.headers.get(b"Test-Header-Injection");
     9    message[u'test_header_injection'] = isomorphic_decode(header) if header else None
    710
    8     header = request.headers.get("Sec-Required-CSP");
    9     message['required_csp'] = header if header else None
     11    header = request.headers.get(b"Sec-Required-CSP");
     12    message[u'required_csp'] = isomorphic_decode(header) if header else None
    1013
    11     second_level_iframe_code = ""
    12     if "include_second_level_iframe" in request.GET:
    13        if "second_level_iframe_csp" in request.GET and request.GET["second_level_iframe_csp"] != "":
    14          second_level_iframe_code = '''<script>
     14    second_level_iframe_code = u""
     15    if b"include_second_level_iframe" in request.GET:
     16       if b"second_level_iframe_csp" in request.GET and request.GET[b"second_level_iframe_csp"] != b"":
     17         second_level_iframe_code = u'''<script>
    1518            var i2 = document.createElement('iframe');
    1619            i2.src = 'echo-required-csp.py';
    1720            i2.csp = "{0}";
    1821            document.body.appendChild(i2);
    19             </script>'''.format(request.GET["second_level_iframe_csp"])
     22            </script>'''.format(isomorphic_decode(request.GET[b"second_level_iframe_csp"]))
    2023       else:
    21          second_level_iframe_code = '''<script>
     24         second_level_iframe_code = u'''<script>
    2225            var i2 = document.createElement('iframe');
    2326            i2.src = 'echo-required-csp.py';
     
    2528            </script>'''
    2629
    27     return [("Content-Type", "text/html"), ("Allow-CSP-From", "*")], '''
     30    return [(b"Content-Type", b"text/html"), (b"Allow-CSP-From", b"*")], u'''
    2831<!DOCTYPE html>
    2932<html>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/support/testharness-helper.sub.js

    r263605 r279838  
    1818function getOrigin() {
    1919  var url = new URL("http://{{host}}:{{ports[http][0]}}/");
    20   return url.toString();
     20  return url.origin;
    2121}
    2222
     
    139139      if (e.source != i.contentWindow)
    140140        return;
     141      if (!e.data.securitypolicyviolation)
     142        return;
    141143      assert_equals(e.data["blockedURI"], blockedURI);
    142144      t.done();
    143145    }));
    144146  } else {
    145     // Assert iframe loads.  Wait for both the load event and the postMessage.
     147    // Assert iframe loads.  Wait for the load event, the postMessage from the
     148    // script and the img load event.
     149    let postMessage_received = false;
     150    let img_loaded = false;
    146151    window.addEventListener('message', t.step_func(e => {
    147152      if (e.source != i.contentWindow)
    148153        return;
    149       assert_true(loaded[urlId]);
    150       if (i.onloadReceived)
     154      if (e.data.loaded) {
     155        assert_true(loaded[urlId]);
     156        postMessage_received = true;
     157      } else if (e.data === "img.loaded")
     158        img_loaded = true;
     159
     160      if (i.onloadReceived && postMessage_received && img_loaded)
    151161        t.done();
    152162    }));
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/support/w3c-import.log

    r263605 r279838  
    1818/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/support/echo-policy-multiple.py
    1919/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/support/echo-required-csp.py
     20/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/support/embed-img-and-message-top.html
    2021/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/support/executor.html
    2122/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/support/testharness-helper.sub.js
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/w3c-import.log

    r263605 r279838  
    1515------------------------------------------------------------------------
    1616List of files:
     17/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/META.yml
    1718/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/allow_csp_from-header.html
    1819/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/blocked-iframe-are-cross-origin.html
     20/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/change-csp-attribute-and-history-navigation.html
    1921/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/idlharness.window.js
    2022/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/iframe-csp-attribute.html
     
    3133/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-none.html
    3234/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-self.html
     35/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-source_list-wildcards.html
    3336/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-strict_dynamic.html
    3437/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/subsumption_algorithm-unsafe_eval.html
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/form-action/form-action-src-redirect-blocked.sub-expected.txt

    r267651 r279838  
    55
    66
    7 FAIL Expecting logs: ["violated-directive=form-action","TEST COMPLETE"] assert_unreached: Logging timeout, expected logs violated-directive=form-action not sent. Reached unreachable code
     7FAIL Expecting logs: ["violated-directive=form-action","blocked-uri=http://localhost:8800/common/redirect.py?location=http://www1.localhost:8800/content-security-policy/support/postmessage-fail.html","TEST COMPLETE"] assert_unreached: Logging timeout, expected logs violated-directive=form-action,blocked-uri=http://localhost:8800/common/redirect.py?location=http://www1.localhost:8800/content-security-policy/support/postmessage-fail.html not sent. Reached unreachable code
    88
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/form-action/form-action-src-redirect-blocked.sub.html

    r246330 r279838  
    88    <script src="/resources/testharness.js"></script>
    99    <script src="/resources/testharnessreport.js"></script>
    10     <script src='../support/logTest.sub.js?logs=["violated-directive=form-action","TEST COMPLETE"]'></script>
     10    <script src='../support/logTest.sub.js?logs=["violated-directive=form-action","blocked-uri=http://{{hosts[][]}}:{{ports[http][0]}}/common/redirect.py?location=http://{{domains[www1]}}:{{ports[http][0]}}/content-security-policy/support/postmessage-fail.html","TEST COMPLETE"]'></script>
    1111    <script src="../support/alertAssert.sub.js?alerts=[]"></script>
    1212    <script>
    1313        window.addEventListener('securitypolicyviolation', function(e) {
    1414            log('violated-directive=' + e.violatedDirective);
     15            log('blocked-uri=' + e.blockedURI);
    1516        });
    1617        window.addEventListener("message", function(event) {
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-same-none-block-expected.txt

    r262312 r279838  
    1 Blocked access to external URL http://www1.localhost:8801/content-security-policy/frame-ancestors/support/frame-ancestors.sub.html?policy=&#x27;none&#x27;
     1Blocked access to external URL http://www1.localhost:8801/content-security-policy/frame-ancestors/support/frame-ancestors.sub.html?policy=%27none%27
    22
    33
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-same-self-block-expected.txt

    r262312 r279838  
    1 Blocked access to external URL http://www1.localhost:8801/content-security-policy/frame-ancestors/support/frame-ancestors.sub.html?policy=&#x27;self&#x27;
     1Blocked access to external URL http://www1.localhost:8801/content-security-policy/frame-ancestors/support/frame-ancestors.sub.html?policy=%27self%27
    22
    33
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-same-star-allow.html

    r246330 r279838  
    22<html>
    33<head>
     4    <meta name="timeout" content="long">
    45    <script src="/resources/testharness.js"></script>
    56    <script src="/resources/testharnessreport.js"></script>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/frame-ancestors-nested-same-in-same-self-allow-expected.txt

    r262312 r279838  
    11
    22
    3 FAIL A 'frame-ancestors' CSP directive with a value 'same' should block render in same-origin nested frames. assert_unreached: Inner IFrame msg: The IFrame should not have been blocked. It was. Reached unreachable code
     3PASS A 'frame-ancestors' CSP directive with a value 'same' should block render in same-origin nested frames.
    44
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/frame-ancestors-none-block-expected.txt

    r267651 r279838  
    11
    22
     3PASS frame-ancestors-none-block
    34PASS A 'frame-ancestors' CSP directive with a value 'none' should block rendering.
    45
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/frame-ancestors-none-block.html

    r246330 r279838  
    77</head>
    88<body>
    9     <script>
    10         test = async_test("A 'frame-ancestors' CSP directive with a value 'none' should block rendering.");
     9  <script>
     10    async_test(t => {
     11      window.addEventListener('securitypolicyviolation', t.step_func(function(e) {
     12        if (e.violatedDirective === 'frame-ancestors')
     13          assert_unreached('No securitypolicyviolation event shoud be raised in the parent.');
     14      }));
     15      t.step_timeout(function() { t.done(); }, 2000);
     16    });
    1117
    12         sameOriginFrameShouldBeBlocked("'none'");
    13     </script>
     18    test = async_test("A 'frame-ancestors' CSP directive with a value 'none' should block rendering.");
     19
     20    sameOriginFrameShouldBeBlocked("'none'");
     21  </script>
    1422</body>
    1523</html>
    16 
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/report-blocked-frame.sub.html

    r254133 r279838  
    88</head>
    99<body>
    10   <iframe src="support/content-security-policy.sub.html?policy=report-uri%20../../support/report.py%3Fop=put%26reportID={{$id:uuid()}}%3B%20frame-ancestors%20'none'"></iframe>
     10  <iframe src="support/content-security-policy.sub.html?policy=report-uri%20/reporting/resources/report.py%3Fop=put%26reportID={{$id:uuid()}}%3B%20frame-ancestors%20'none'"></iframe>
    1111  <script async defer src="../support/checkReport.sub.js?reportField=violated-directive&reportValue=frame-ancestors%20'none'&reportID={{$id}}"></script>
    1212</body>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/report-only-frame.sub.html

    r254133 r279838  
    88</head>
    99<body>
    10   <iframe src="support/content-security-policy-report-only.sub.html?policy=report-uri%20../../support/report.py%3Fop=put%26reportID={{$id:uuid()}}%3B%20frame-ancestors%20'none'"></iframe>
     10  <iframe src="support/content-security-policy-report-only.sub.html?policy=report-uri%20/reporting/resources/report.py%3Fop=put%26reportID={{$id:uuid()}}%3B%20frame-ancestors%20'none'"></iframe>
    1111  <script async defer src="../support/checkReport.sub.js?reportField=violated-directive&reportValue=frame-ancestors%20'none'&reportID={{$id}}"></script>
    1212</body>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/support/frame-in-frame.sub.html

    r246330 r279838  
    55    <script src='/resources/testharnessreport.js'></script>
    66    <script src='/content-security-policy/frame-ancestors/support/frame-ancestors-test.sub.js'></script>
     7
     8    <span id="escape">{{GET[policy]}}</span>
     9
    710    <script>
    811        test = async_test("Testing a {{GET[child]}}-origin child with a policy of {{GET[policy]}} nested in a {{GET[parent]}}-origin parent");
    9         originFrameShouldBe("{{GET[child]}}", "{{GET[expectation]}}", "{{GET[policy]]}}");
     12        const policy = document.getElementById("escape").textContent;
     13        originFrameShouldBe("{{GET[child]}}", "{{GET[expectation]}}", policy);
    1014    </script>
    1115</body>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-about-blank-allowed-by-default.sub.html

    r246330 r279838  
    1010    <script src='../support/logTest.sub.js?logs=["PASS"]'></script>
    1111    <script src="../support/alertAssert.sub.js?alerts=[]"></script>
    12    
     12
    1313    <p>These frames should not be blocked by Content-Security-Policy.
    1414        It&apos;s pointless to block about:blank iframes because
     
    1919            log("Fail");
    2020        });
    21     </script>   
    22    
     21    </script>
     22
    2323    <iframe src="about:blank"></iframe>
    2424    <object type="text/html" data="about:blank"></object>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-about-blank-allowed-by-scheme.sub.html

    r246330 r279838  
    1717            log("Fail");
    1818        });
    19     </script>   
    20    
     19    </script>
     20
    2121    <iframe src="about:blank"></iframe>
    2222    <div id="log"></div>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-allowed.sub.html

    r246330 r279838  
    1212            log("Fail");
    1313        });
    14        
     14
    1515        window.addEventListener("message", function(event) {
    1616            alert_assert(event.data);
     
    2828                for (var i = 0; i < expected_alerts.length; i++) {
    2929                    if (expected_alerts[i] == msg) {
    30                         assert_true(expected_alerts[i] == msg);
     30                        assert_equals(expected_alerts[i], msg);
    3131                        expected_alerts.splice(i, 1);
    3232                        if (expected_alerts.length == 0) {
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-blocked.sub.html

    r246330 r279838  
    1313            log("violated-directive=" + e.violatedDirective);
    1414        });
    15        
     15
    1616        window.addEventListener("message", function(event) {
    1717            alert_assert(event.data);
     
    2626                for (var i = 0; i < expected_alerts.length; i++) {
    2727                    if (expected_alerts[i] == msg) {
    28                         assert_true(expected_alerts[i] == msg);
     28                        assert_equals(expected_alerts[i], msg);
    2929                        expected_alerts.splice(i, 1);
    3030                        if (expected_alerts.length == 0) {
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-cross-origin-load.sub.html

    r246330 r279838  
    1313            log("violated-directive=" + e.violatedDirective);
    1414        });
    15        
     15
    1616        window.addEventListener("message", function(event) {
    1717            alert_assert(event.data);
     
    2929                for (var i = 0; i < expected_alerts.length; i++) {
    3030                    if (expected_alerts[i] == msg) {
    31                         assert_true(expected_alerts[i] == msg);
     31                        assert_equals(expected_alerts[i], msg);
    3232                        expected_alerts.splice(i, 1);
    3333                        if (expected_alerts.length == 0) {
     
    4343
    4444    </script>
    45    
     45
    4646    <p>
    4747        IFrames blocked by CSP should generate a 'load', not 'error' event, regardless of blocked state. This means they appear to be normal cross-origin loads, thereby not leaking URL information directly to JS.
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-same-document.sub.html

    r263605 r279838  
    55<script>
    66    let crossOriginUrl =
    7       "http://www1.{{host}}:{{ports[http][0]}}/content-security-policy/support/frame.html";
     7      "http://www1.{{host}}:{{ports[http][0]}}/content-security-policy/frame-src/support/frame.html";
    88
    9     async_test(async test => {
    10       test.done();
     9    promise_test(async test => {
    1110      let iframe = document.createElement("iframe");
    1211      document.body.appendChild(iframe);
     
    1918        await violation;
    2019      }
    21 
    22       test.done();
    2320    }, "Same-document navigation in an iframe blocked by CSP frame-src");
    2421</script>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-self-unique-origin.html

    r246330 r279838  
    3636        `);
    3737        if (window.async_test) {
    38             async_test(t => { 
     38            async_test(t => {
    3939                window.addEventListener("message", e => {
    4040                    if (e.data == "Test PASS")
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/w3c-import.log

    r263605 r279838  
    2323/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-redirect.html.headers
    2424/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-same-document-meta.sub.html
    25 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-same-document.html.headers
    2625/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-same-document.sub.html
     26/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-same-document.sub.html.headers
     27/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-sandboxed-allowed.html
     28/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-sandboxed-allowed.html.headers
    2729/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/frame-src/frame-src-self-unique-origin.html
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/duplicate-directive.sub.html

    r246330 r279838  
    44<head>
    55    <!-- Programmatically converted from a WebKit Reftest, please forgive resulting idiosyncracies.-->
    6     <meta http-equiv="Content-Security-Policy" content="script-src 'self' 'unsafe-inline' 'unsafe-inline'; script-src 'none'; connect-src 'self';">   
     6    <meta http-equiv="Content-Security-Policy" content="script-src 'self' 'unsafe-inline' 'unsafe-inline'; script-src 'none'; connect-src 'self';">
    77    <title>duplicate-directive</title>
    88    <script src="/resources/testharness.js"></script>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/filesystem-urls-match-filesystem.sub.html

    r246330 r279838  
    2020            log("Fail");
    2121        });
    22    
     22
    2323        if(!window.webkitRequestFileSystem) {
    2424            t_log.set_status(t_log.NOTRUN, "No filesystem:// support, cannot run test.");
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/generic-0_1-img-src.html

    r246330 r279838  
    1616      var onerrorFired = false;
    1717      var t_spv = async_test("Should fire violation events for every failed violation");
    18      
     18
    1919      window.addEventListener("securitypolicyviolation", t_spv.step_func_done(function(e) {
    2020          assert_equals(e.violatedDirective, "img-src");
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/generic-0_10.sub.html

    r254133 r279838  
    99      var t = async_test("Test that script does not fire violation event");
    1010      window.addEventListener("securitypolicyviolation", t.unreached_func("Should not have fired a violation event"));
    11      
     11
    1212      var head = document.getElementsByTagName('head')[0];
    1313      var script = document.createElement('script');
     
    1616      head.appendChild(script);
    1717    </script>
    18    
     18
    1919    <script>
    2020        t.done();
    21     </script>   
     21    </script>
    2222</head>
    2323<body>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/generic-0_8_1.sub.html

    r254133 r279838  
    33<head>
    44    <title>test wildcard host name matching (asterisk as part of a subdomain is not accepted)</title>
    5     <meta http-equiv="Content-Security-Policy" content="script-src 'self' *w.{{host}}:{{ports[http][0]}} w*.{{host}}:{{ports[http][0]}} 'unsafe-inline';">
    6     <script src='/resources/testharness.js'></script>
    7     <script src='/resources/testharnessreport.js'></script>
    8     <script src='wildcardHostTestFailure.js'></script>
    95    <script>
    106      var t_spv = async_test("Should fire violation events for every failed violation");
     
    2420      head.appendChild(script);
    2521    </script>
     22    <meta http-equiv="Content-Security-Policy" content="script-src 'self' *w.{{host}}:{{ports[http][0]}} w*.{{host}}:{{ports[http][0]}} 'unsafe-inline';">
     23    <script src='/resources/testharness.js'></script>
     24    <script src='/resources/testharnessreport.js'></script>
     25    <script src='wildcardHostTestFailure.js'></script>
    2626</head>
    2727<body>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/generic-0_9.sub.html

    r254133 r279838  
    1313        t.done();
    1414      });
    15      
     15
    1616      var head = document.getElementsByTagName('head')[0];
    1717      var script = document.createElement('script');
     
    2323<body>
    2424    <h1>test wildcard port number matching</h1>
    25     <div id='log'></div> 
     25    <div id='log'></div>
    2626</body>
    2727</html>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/no-default-src.sub.html.sub.headers

    r246330 r279838  
    44Pragma: no-cache
    55Set-Cookie: no-default-src={{$id:uuid()}}; Path=/content-security-policy/generic/
    6 Content-Security-Policy: foobar; report-uri  ../support/report.py?op=put&reportID={{$id}}
     6Content-Security-Policy: foobar; report-uri  /reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/only-valid-whitespaces-are-allowed.html

    r246330 r279838  
    4343      if (test.csp.indexOf("\u000A") == -1 && test.csp.indexOf("\u000D") == -1) {
    4444        async_test(t => {
    45           var url = "support/load_img_and_post_result_meta.sub.html?csp=" + encodeURIComponent(test.csp);
     45          var url = "support/load_img_and_post_result_header.html?csp=" + encodeURIComponent(test.csp);
    4646          test_image_loads_as_expected(test, t, url);
    4747        }, test.name + " - HTTP header");
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/policy-inherited-correctly-by-plznavigate.html.sub.headers

    r246330 r279838  
    33Pragma: no-cache
    44Set-Cookie: policy-inherited-correctly-by-plznavigate={{$id:uuid()}}; Path=/content-security-policy/generic/
    5 Content-Security-Policy: frame-src 'none'; script-src 'self' 'unsafe-inline'; report-uri  ../support/report.py?op=put&reportID={{$id}}
     5Content-Security-Policy: frame-src 'none'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/support/304-response.py

    r246330 r279838  
    11def main(request, response):
    2     if request.headers.get("If-None-Match"):
     2    if request.headers.get(b"If-None-Match"):
    33        # we are now receing the second request, we will send back a different CSP
    44        # with the 304 response
    55        response.status = 304
    6         headers = [("Content-Type", "text/html"),
    7                    ("Content-Security-Policy", "script-src 'nonce-def' 'sha256-IIB78ZS1RMMrAWpsLg/RrDbVPhI14rKm3sFOeKPYulw=';"),
    8                    ("Cache-Control", "private, max-age=0, must-revalidate"),
    9                    ("ETag", "123456")]
    10         return headers, ""
     6        headers = [(b"Content-Type", b"text/html"),
     7                   (b"Content-Security-Policy", b"script-src 'nonce-def' 'sha256-IIB78ZS1RMMrAWpsLg/RrDbVPhI14rKm3sFOeKPYulw=';"),
     8                   (b"Cache-Control", b"private, max-age=0, must-revalidate"),
     9                   (b"ETag", b"123456")]
     10        return headers, u""
    1111    else:
    12         headers = [("Content-Type", "text/html"),
    13                    ("Content-Security-Policy", "script-src 'nonce-abc' 'sha256-IIB78ZS1RMMrAWpsLg/RrDbVPhI14rKm3sFOeKPYulw=';"),
    14                    ("Cache-Control", "private, max-age=0, must-revalidate"),
    15                    ("Etag", "123456")]
    16         return headers, '''
     12        headers = [(b"Content-Type", b"text/html"),
     13                   (b"Content-Security-Policy", b"script-src 'nonce-abc' 'sha256-IIB78ZS1RMMrAWpsLg/RrDbVPhI14rKm3sFOeKPYulw=';"),
     14                   (b"Cache-Control", b"private, max-age=0, must-revalidate"),
     15                   (b"Etag", b"123456")]
     16        return headers, u'''
    1717<!DOCTYPE html>
    1818<html>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/w3c-import.log

    r254133 r279838  
    3535/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/generic-0_8_1.sub.html
    3636/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/generic-0_9.sub.html
     37/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/invalid-characters-in-policy.html
    3738/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/negativeTests.js
    3839/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/no-default-src.sub.html
     
    4445/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/policy-inherited-correctly-by-plznavigate.html.sub.headers
    4546/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/positiveTest.js
     47/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/test-case.sub.js
    4648/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/unreached.js
    4749/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/generic/wildcardHostTest.js
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/img-src/icon-allowed.sub.html

    r246330 r279838  
    1111    var t = async_test("Test that image loads");
    1212    window.addEventListener("securitypolicyviolation", t.unreached_func("Should not have triggered any violation events"));
    13    
     13
    1414    function createLink(rel, src) {
    1515        var link = document.createElement('link');
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/img-src/icon-blocked.sub.html

    r246330 r279838  
    1515      assert_true(e.blockedURI.endsWith('/support/fail.png'));
    1616    }));
    17    
     17
    1818    function createLink(rel, src) {
    1919        var link = document.createElement('link');
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/img-src/img-src-self-unique-origin.html

    r246330 r279838  
    3636        `);
    3737        if (window.async_test) {
    38             async_test(t => { 
     38            async_test(t => {
    3939                window.addEventListener("message", e => {
    4040                    if (e.data == "Test PASS")
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/img-src/report-blocked-data-uri.sub.html

    r246330 r279838  
    1818       });
    1919    </script>
    20    
     20
    2121    <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==">
    2222    <div id="log"></div>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/document-write-iframe.html

    r246330 r279838  
    44  <script src="/resources/testharness.js"></script>
    55  <script src="/resources/testharnessreport.js"></script>
    6 
     6  <title>document.open() does not change Content Security Policies</title>
    77</head>
    88<body>
    99  <script>
    10     var t0 = async_test("Image loaded in srcdoc iframe using document.write is blocked");
    11     var t1 = async_test("Image loaded in normal iframe using document.write is blocked");
    12     var t2 = async_test("Image loaded directly in simple srcdoc iframe is blocked");
     10    let message_from = (w) => {
     11      return new Promise(resolve => {
     12        let listener = msg => {
     13          if (msg.source != w)
     14            return;
     15          window.removeEventListener('message', listener);
     16          resolve(msg.data);
     17        };
     18        window.addEventListener('message', listener);
     19      });
     20    };
    1321
    14     window.onmessage = function(e) {
    15       var current_test;
    16       if (e.data.type == "spv0") {
    17         current_test = t0;
    18       } else if (e.data.type == "spv1") {
    19         current_test = t1;
    20       } else if (e.data.type == "spv2") {
    21         current_test = t2;
    22       } else {
    23         t0.step(function() {assert_true(false, "Unexpected message received from child frames")});
    24         t1.step(function() {assert_true(false, "Unexpected message received from child frames")});
    25         t2.step(function() {assert_true(false, "Unexpected message received from child frames")});
    26       }
     22    var documentBody = function(should_load) {
     23      let image = should_load ? "pass.png" : "fail.png";
     24      return `
     25      <script>
     26        function loaded() {
     27          window.top.postMessage("loaded", '*');
     28        };
     29        window.addEventListener('securitypolicyviolation', function(e) {
     30          window.top.postMessage("blocked", '*');
     31        });
     32      </scr`+`ipt>
     33      <img src='/content-security-policy/support/${image}' onload='loaded()'>`;
     34    };
    2735
    28       current_test.step(function() {
    29         assert_equals(e.data.violatedDirective, 'img-src');
    30         current_test.done();
    31       });
    32     }
    33   </script>
     36    promise_test(async () => {
     37      let iframe = document.createElement('iframe');
     38      document.body.appendChild(iframe);
    3439
    35   <!--As discovered thanks to crbug.com/920531, there is a bug in CSP where the
    36       CSP is not inherited when using document.open/document.write to edit a
    37       document's contents. -->
    38   <iframe id="frame1" srcdoc=""></iframe>
     40      let msg = message_from(iframe.contentWindow);
     41      let doc = iframe.contentWindow.document;
     42      doc.open();
     43      doc.write("<html><body>" + documentBody(false) + "</body></html>");
     44      doc.close();
     45      assert_equals(await msg, "blocked");
     46    }, "document.open() keeps inherited CSPs on empty iframe.");
    3947
    40   <!-- This is speculatively correct https://github.com/whatwg/html/issues/4510 -->
    41   <iframe id="frame2" src="/content-security-policy/common/blank.html"></iframe>
     48    promise_test(async () => {
     49      let iframe = document.createElement('iframe');
     50      let loaded = new Promise(resolve => iframe.onload = resolve);
     51      iframe.src = "/common/blank.html";
     52      document.body.appendChild(iframe);
     53      await loaded;
    4254
    43   <!--<script>
    44         window.addEventListener('securitypolicyviolation', function(e) {
    45           window.top.postMessage({type: 'spv2', violatedDirective: e.violatedDirective}, '*');
    46         });
    47       </script>
    48       <img src='/content-security-policy/support/fail.png'>
    49   -->
    50   <iframe srcdoc="<script>window.addEventListener('securitypolicyviolation', function(e) {window.top.postMessage({type: 'spv2', violatedDirective: e.violatedDirective}, '*');});</script><img src='/content-security-policy/support/fail.png'>"></iframe>
    51   <script>
    52     var frames = ['frame1', 'frame2'];
    53     for (var i = 0; i < frames.length; i++) {
    54       var body_text = ['<script>',
    55                        ' window.addEventListener("securitypolicyviolation", function(e) {',
    56                        '  window.top.postMessage({type: "spv'+ i + '", violatedDirective: e.violatedDirective}, "*");',
    57                        ' });',
    58                        '</scr' + 'ipt>',
    59                        '<img src="/content-security-policy/support/fail.png">'].join('\n');
     55      let msg = message_from(iframe.contentWindow);
     56      let doc = iframe.contentWindow.document;
     57      doc.open();
     58      doc.write("<html><body>" + documentBody(true) + "</body></html>");
     59      doc.close();
     60      assert_equals(await msg, "loaded");
     61    }, "document.open() does not change delivered CSPs.");
    6062
    61       var e = document.getElementById(frames[i]);
    62       var n = e.contentWindow.document;
    63       n.open();
    64       n.write("<html><body>" + body_text + "</body></html>");
    65       n.close();
    66     }
    6763  </script>
    6864</body>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/iframe-all-local-schemes.sub-expected.txt

    r267651 r279838  
    11
    22PASS <iframe>'s about:blank inherits policy.
     3PASS window about:blank inherits policy.
    34PASS <iframe srcdoc>'s inherits policy.
    45PASS <iframe src='blob:...'>'s inherits policy.
     6PASS window url='blob:...' inherits policy.
    57PASS <iframe src='data:...'>'s inherits policy.
    68PASS <iframe src='javascript:...'>'s inherits policy (static <img> is blocked)
     9PASS window url='javascript:...'>'s inherits policy (static <img> is blocked)
    710PASS <iframe src='javascript:...'>'s inherits policy (dynamically inserted <img> is blocked)
    811PASS <iframe sandbox src='blob:...'>'s inherits policy. (opaque origin sandbox)
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/iframe-all-local-schemes.sub.html

    r263605 r279838  
    1818  }
    1919
     20  function wait_for_error_from_window(opened_window, test) {
     21    window.addEventListener('message', test.step_func(e => {
     22      if (e.source != opened_window)
     23        return;
     24      assert_equals(e.data, "error");
     25      opened_window.close();
     26      test.done();
     27    }));
     28  }
     29
    2030  async_test(t => {
    2131    var i = document.createElement('iframe');
     
    2838    img.src = "{{location[server]}}/images/red-16x16.png";
    2939  }, "<iframe>'s about:blank inherits policy.");
     40
     41  async_test(t => {
     42    var w = window.open("about:blank");
     43
     44    let then = t.step_func(() => {
     45      then = () => {};
     46      var img = w.document.createElement('img');
     47      img.onerror = t.step_func_done(_ => w.close());
     48      img.onload = t.unreached_func();
     49      w.document.body.appendChild(img);
     50      img.src = "{{location[server]}}/images/red-16x16.png";
     51    });
     52
     53    // There are now interoperable way to wait for the initial about:blank
     54    // document to load. Chrome loads it synchronously, hence we can't wait for
     55    // w.onload. On the other side Firefox loads the initial empty document
     56    // later and we can wait for the onload event.
     57    w.onload = then;
     58    setTimeout(then, 200);
     59
     60    // Navigations to about:blank happens synchronously. There is no need to
     61    // wait for the document to load.
     62  }, "window about:blank inherits policy.");
    3063
    3164  async_test(t => {
     
    6093
    6194  async_test(t => {
     95    var b = new Blob(
     96      [`
     97        <img src='{{location[server]}}/images/red-16x16.png'
     98          onload='window.opener.postMessage("load", "*");'
     99          onerror='window.opener.postMessage("error", "*");'
     100        >
     101      `], {type:"text/html"});
     102    let url = URL.createObjectURL(b);
     103    var w = window.open(url);
     104    wait_for_error_from_window(w, t);
     105  }, "window url='blob:...' inherits policy.");
     106
     107  async_test(t => {
    62108    var i = document.createElement('iframe');
    63109    i.src = `data:text/html,<img src='{{location[server]}}/images/red-16x16.png'
     
    70116    document.body.appendChild(i);
    71117  }, "<iframe src='data:...'>'s inherits policy.");
     118
     119  // Opening a window toward a data-url isn't allowed anymore. Hence, it can't
     120  // be tested.
    72121
    73122  async_test(t => {
     
    82131    document.body.appendChild(i);
    83132  }, "<iframe src='javascript:...'>'s inherits policy (static <img> is blocked)");
     133
     134  async_test(t => {
     135    let url = `javascript:"<img src='{{location[server]}}/images/red-16x16.png'
     136      onload='window.opener.postMessage(\\"load\\", \\"*\\");'
     137      onerror='window.opener.postMessage(\\"error\\", \\"*\\");'
     138    >"`;
     139
     140    let w = window.open(url);
     141    wait_for_error_from_window(w, t);
     142  }, "window url='javascript:...'>'s inherits policy (static <img> is blocked)");
    84143
    85144  // Same as the previous javascript-URL test, but instead of loading the <img>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/sandboxed-blob-scheme.html.sub.headers

    r246330 r279838  
    33Pragma: no-cache
    44Set-Cookie: sandboxed-blob-scheme={{$id:uuid()}}; Path=/content-security-policy/inheritance/
    5 Content-Security-Policy: script-src 'nonce-abc'; report-uri http://{{host}}:{{ports[http][0]}}/content-security-policy/support/report.py?op=put&reportID={{$id}}
     5Content-Security-Policy: script-src 'nonce-abc'; report-uri http://{{host}}:{{ports[http][0]}}/reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/sandboxed-data-scheme.html.sub.headers

    r246330 r279838  
    33Pragma: no-cache
    44Set-Cookie: sandboxed-data-scheme={{$id:uuid()}}; Path=/content-security-policy/inheritance/
    5 Content-Security-Policy: script-src 'nonce-abc'; report-uri http://{{host}}:{{ports[http][0]}}/content-security-policy/support/report.py?op=put&reportID={{$id}}
     5Content-Security-Policy: script-src 'nonce-abc'; report-uri http://{{host}}:{{ports[http][0]}}/reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/support/navigate-self-to-blob.html.sub.headers

    r246330 r279838  
    22Cache-Control: no-store, no-cache, must-revalidate
    33Pragma: no-cache
    4 Content-Security-Policy: {{GET[csp]}}; report-uri http://{{host}}:{{ports[http][0]}}/content-security-policy/support/report.py?op=put&reportID={{GET[report_id]}}
     4Content-Security-Policy: {{GET[csp]}}; report-uri http://{{host}}:{{ports[http][0]}}/reporting/resources/report.py?op=put&reportID={{GET[report_id]}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/support/w3c-import.log

    r263605 r279838  
    1616List of files:
    1717/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/support/empty.html
     18/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/support/iframe-do.sub.html
     19/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/support/javascript-url-srcdoc-cross-origin-iframe-inheritance-helper.sub.html
     20/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/support/message-opener-and-navigate-back.html
     21/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/support/message-top-and-navigate-back.html
     22/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/support/navigate-parent-to-blob.html
    1823/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/support/navigate-self-to-blob.html
    1924/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/support/navigate-self-to-blob.html.sub.headers
     25/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/support/navigate-self-to-javascript.html
     26/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/support/postmessage-opener.html
     27/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/support/postmessage-top.html
    2028/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/support/srcdoc-child-frame.html
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/unsandboxed-blob-scheme.html.sub.headers

    r246330 r279838  
    33Pragma: no-cache
    44Set-Cookie: unsandboxed-blob-scheme={{$id:uuid()}}; Path=/content-security-policy/inheritance/
    5 Content-Security-Policy: script-src 'nonce-abc'; report-uri http://{{host}}:{{ports[http][0]}}/content-security-policy/support/report.py?op=put&reportID={{$id}}
     5Content-Security-Policy: script-src 'nonce-abc'; report-uri http://{{host}}:{{ports[http][0]}}/reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/unsandboxed-data-scheme.html.sub.headers

    r246330 r279838  
    33Pragma: no-cache
    44Set-Cookie: unsandboxed-data-scheme={{$id:uuid()}}; Path=/content-security-policy/inheritance/
    5 Content-Security-Policy: script-src 'nonce-abc'; report-uri http://{{host}}:{{ports[http][0]}}/content-security-policy/support/report.py?op=put&reportID={{$id}}
     5Content-Security-Policy: script-src 'nonce-abc'; report-uri http://{{host}}:{{ports[http][0]}}/reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/w3c-import.log

    r263605 r279838  
    1717/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/blob-url-in-child-frame-self-navigate-inherits.sub.html
    1818/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/blob-url-in-main-window-self-navigate-inherits.sub.html
     19/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/blob-url-inherits-from-initiator.sub.html
    1920/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/document-write-iframe.html
    2021/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/frame-src-javascript-url.html
     22/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/history-iframe.sub.html
     23/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/history.sub.html
    2124/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/iframe-all-local-schemes-inherit-self.sub.html
    2225/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/iframe-all-local-schemes.sub.html
    2326/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/iframe-srcdoc-inheritance.html
     27/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/inheritance-from-initiator.sub.html
    2428/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/inherited-csp-list-modifications-are-local.html
     29/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/javascript-url-open-in-main-window.html
     30/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/javascript-url-srcdoc-cross-origin-iframe-inheritance.html
     31/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/location-reload.html
    2532/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/sandboxed-blob-scheme.html
    2633/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/sandboxed-blob-scheme.html.sub.headers
     
    3138/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/unsandboxed-data-scheme.html
    3239/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/unsandboxed-data-scheme.html.sub.headers
     40/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/window-open-local-after-network-scheme.sub.html
    3341/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inheritance/window.html
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/support/connect-src-allow.sub.js

    r254133 r279838  
    22importScripts("{{location[server]}}/content-security-policy/support/testharness-helper.js");
    33
     4let base_same_origin_url =
     5      "{{location[server]}}/content-security-policy/support/resource.py";
     6let base_cross_origin_url =
     7      "https://{{hosts[][www]}}:{{ports[https][1]}}" +
     8      "/content-security-policy/support/resource.py";
     9
    410// Same-origin
    5 async_test(t => {
    6   var url = "{{location[server]}}/content-security-policy/support/resource.py?same-origin-fetch";
     11promise_test(t => {
     12  let url = `${base_same_origin_url}?same-origin-fetch`;
    713  assert_no_csp_event_for_url(t, url);
    814
    9   fetch(url)
    10     .then(t.step_func_done(r => assert_equals(r.status, 200)));
    11 }, "Same-origin 'fetch()' in " + self.location.protocol + self.location.search);
     15  return fetch(url)
     16    .then(t.step_func(r => assert_equals(r.status, 200)));
     17}, "Same-origin 'fetch()' in " + self.location.protocol + " without CSP");
    1218
    13 async_test(t => {
    14   var url = "{{location[server]}}/content-security-policy/support/resource.py?same-origin-xhr";
     19// XHR is not available in service workers.
     20if (self.XMLHttpRequest) {
     21  promise_test(t => {
     22    let url = `${base_same_origin_url}?same-origin-xhr`;
     23    assert_no_csp_event_for_url(t, url);
     24
     25    return new Promise((resolve, reject) => {
     26      let xhr = new XMLHttpRequest();
     27      xhr.open("GET", url);
     28      xhr.onload = resolve;
     29      xhr.onerror = _ => reject("xhr.open should success.");
     30      xhr.send();
     31    });
     32  }, "Same-origin XHR in " + self.location.protocol + " without CSP");
     33}
     34
     35// Cross-origin
     36promise_test(t => {
     37  let url = `${base_cross_origin_url}?cross-origin-fetch`;
    1538  assert_no_csp_event_for_url(t, url);
    1639
    17   var xhr = new XMLHttpRequest();
    18   xhr.open("GET", url);
    19   xhr.onload = t.step_func_done();
    20   xhr.onerror = t.unreached_func();
    21   xhr.send();
    22 }, "Same-origin XHR in " + self.location.protocol + self.location.search);
     40  return fetch(url)
     41    .then(t.step_func(r => assert_equals(r.status, 200)));
     42}, "Cross-origin 'fetch()' in " + self.location.protocol + " without CSP");
    2343
    24 // Cross-origin
    25 async_test(t => {
    26   var url = "http://{{hosts[alt][]}}:{{ports[http][1]}}/content-security-policy/support/resource.py?cross-origin-fetch";
     44// XHR is not available in service workers.
     45if (self.XMLHttpRequest) {
     46  promise_test(t => {
     47    let url = `${base_cross_origin_url}?cross-origin-xhr`;
     48    assert_no_csp_event_for_url(t, url);
     49
     50    return new Promise((resolve, reject) => {
     51      let xhr = new XMLHttpRequest();
     52      xhr.open("GET", url);
     53      xhr.onload = resolve;
     54      xhr.onerror = _ => reject("xhr.open should success.");
     55      xhr.send();
     56    });
     57  }, "Cross-origin XHR in " + self.location.protocol + " without CSP");
     58}
     59
     60// Same-origin redirecting to cross-origin
     61promise_test(t => {
     62  let url = `{{location[server]}}/common/redirect-opt-in.py?` +
     63      `status=307&location=${base_cross_origin_url}?cross-origin-fetch`;
    2764  assert_no_csp_event_for_url(t, url);
    2865
    29   fetch(url)
    30     .then(t.step_func_done(r => assert_equals(r.status, 200)));
    31 }, "Cross-origin 'fetch()' in " + self.location.protocol + self.location.search);
    32 
    33 async_test(t => {
    34   var url = "http://{{hosts[alt][]}}:{{ports[http][1]}}/content-security-policy/support/resource.py?cross-origin-xhr";
    35   assert_no_csp_event_for_url(t, url);
    36 
    37   var xhr = new XMLHttpRequest();
    38   xhr.open("GET", url);
    39   xhr.onload = t.step_func_done();
    40   xhr.onerror = t.unreached_func();
    41   xhr.send();
    42 }, "Cross-origin XHR in " + self.location.protocol + self.location.search);
    43 
    44 // Same-origin redirecting to cross-origin
    45 async_test(t => {
    46   var url = "{{location[server]}}/common/redirect-opt-in.py?status=307&location=http://{{hosts[alt][]}}:{{ports[http][1]}}/content-security-policy/support/resource.py?cross-origin-fetch";
    47   assert_no_csp_event_for_url(t, url);
    48 
    49   fetch(url)
    50     .then(t.step_func_done(r => assert_equals(r.status, 200)));
    51 }, "Same-origin => cross-origin 'fetch()' in " + self.location.protocol + self.location.search);
     66  return fetch(url)
     67    .then(t.step_func(r => assert_equals(r.status, 200)));
     68}, "Same-origin => cross-origin 'fetch()' in " + self.location.protocol +
     69           " without CSP");
    5270
    5371done();
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/support/connect-src-self.sub.js

    r263605 r279838  
    22importScripts("{{location[server]}}/content-security-policy/support/testharness-helper.js");
    33
     4let base_same_origin_url =
     5      "{{location[server]}}/content-security-policy/support/resource.py";
     6let base_cross_origin_url =
     7      "https://{{hosts[][www]}}:{{ports[https][1]}}" +
     8      "/content-security-policy/support/resource.py";
     9
    410// Same-origin
    511promise_test(t => {
    6   var url = "{{location[server]}}/common/text-plain.txt?same-origin-fetch";
     12  let url = `${base_same_origin_url}?same-origin-fetch`;
    713  assert_no_csp_event_for_url(t, url);
    814
    915  return fetch(url)
    1016    .then(t.step_func(r => assert_equals(r.status, 200)));
    11 }, "Same-origin 'fetch()' in " + self.location.protocol + self.location.search);
     17}, "Same-origin 'fetch()' in " + self.location.protocol +
     18             " with {{GET[test-name]}}");
    1219
    13 promise_test(t => {
    14   var url = "{{location[server]}}/common/text-plain.txt?same-origin-xhr";
    15   assert_no_csp_event_for_url(t, url);
     20// XHR is not available in service workers.
     21if (self.XMLHttpRequest) {
     22  promise_test(t => {
     23    let url = `${base_same_origin_url}?same-origin-xhr`;
     24    assert_no_csp_event_for_url(t, url);
    1625
    17   return new Promise((resolve, reject) => {
    18     var xhr = new XMLHttpRequest();
    19     xhr.open("GET", url);
    20     xhr.onload = t.step_func(resolve);
    21     xhr.onerror = t.step_func(_ => reject("xhr.open should success."));
    22     xhr.send();
    23   });
    24 }, "Same-origin XHR in " + self.location.protocol + self.location.search);
     26    return new Promise((resolve, reject) => {
     27      let xhr = new XMLHttpRequest();
     28      xhr.open("GET", url);
     29      xhr.onload = resolve;
     30      xhr.onerror = _ => reject("xhr.open should success.");
     31      xhr.send();
     32    });
     33  }, "Same-origin XHR in " + self.location.protocol +
     34               " with {{GET[test-name]}}");
     35}
     36
     37let fetch_cross_origin_url = `${base_cross_origin_url}?cross-origin-fetch`;
    2538
    2639// Cross-origin
    2740promise_test(t => {
    28   var url = "http://{{hosts[alt][]}}:{{ports[http][1]}}/common/text-plain.txt?cross-origin-fetch";
     41  let url = fetch_cross_origin_url;
    2942
    3043  return Promise.all([
    31     // TODO(mkwst): A 'securitypolicyviolation' event should fire.
     44    waitUntilCSPEventForURL(t, url),
    3245    fetch(url)
    33       .catch(t.step_func(e => assert_true(e instanceof TypeError)))
     46        .then(t.step_func(_ => assert_unreached(
     47            "cross-origin fetch should have thrown.")))
     48        .catch(t.step_func(e => assert_true(e instanceof TypeError)))
    3449  ]);
    35 }, "Cross-origin 'fetch()' in " + self.location.protocol + self.location.search);
     50}, "Cross-origin 'fetch()' in " + self.location.protocol +
     51             " with {{GET[test-name]}}");
    3652
    37 promise_test(t => {
    38   var url = "http://{{hosts[alt][]}}:{{ports[http][1]}}/common/text-plain.txt?cross-origin-xhr";
     53let xhr_cross_origin_url = `${base_cross_origin_url}?cross-origin-xhr`;
    3954
    40   return Promise.all([
    41     // TODO(mkwst): A 'securitypolicyviolation' event should fire.
    42     new Promise((resolve, reject) => {
    43       var xhr = new XMLHttpRequest();
    44       xhr.open("GET", url);
    45       xhr.onload = t.step_func(_ => reject("xhr.open should have thrown."));
    46       xhr.onerror = t.step_func(resolve);
    47       xhr.send();
    48     })
    49   ]);
    50 }, "Cross-origin XHR in " + self.location.protocol + self.location.search);
     55// XHR is not available in service workers.
     56if (self.XMLHttpRequest) {
     57  promise_test(t => {
     58    let url = xhr_cross_origin_url;
     59
     60    return Promise.all([
     61      waitUntilCSPEventForURL(t, url),
     62      new Promise((resolve, reject) => {
     63        let xhr = new XMLHttpRequest();
     64        xhr.open("GET", url);
     65        xhr.onload = _ => reject("xhr.open should have thrown.");
     66        xhr.onerror = resolve;
     67        xhr.send();
     68      })
     69    ]);
     70  }, "Cross-origin XHR in " + self.location.protocol +
     71               " with {{GET[test-name]}}");
     72}
     73
     74let redirect_url = `{{location[server]}}/common/redirect-opt-in.py?` +
     75      `status=307&location=${fetch_cross_origin_url}`;
    5176
    5277// Same-origin redirecting to cross-origin
    5378promise_test(t => {
    54   var url = "{{location[server]}}/common/redirect-opt-in.py?status=307&location=http://{{hosts[alt][]}}:{{ports[http][1]}}/common/text-plain.txt?cross-origin-fetch";
     79  let url = redirect_url;
    5580
    56   // TODO(mkwst): A 'securitypolicyviolation' event should fire.
    57   return promise_rejects_js(t, TypeError, fetch(url));
    58 }, "Same-origin => cross-origin 'fetch()' in " + self.location.protocol + self.location.search);
     81  return Promise.all([
     82    waitUntilCSPEventForURL(t, url),
     83    fetch(url)
     84        .then(t.step_func(_ => assert_unreached(
     85            "cross-origin redirect should have thrown.")))
     86      .catch(t.step_func(e => assert_true(e instanceof TypeError)))
     87  ]);
     88}, "Same-origin => cross-origin 'fetch()' in " + self.location.protocol +
     89             " with {{GET[test-name]}}");
     90
     91let expected_blocked_urls = self.XMLHttpRequest
     92    ? [ fetch_cross_origin_url, xhr_cross_origin_url, redirect_url ]
     93    : [ fetch_cross_origin_url, redirect_url ];
     94
     95promise_test(async t => {
     96  let report_url = `{{location[server]}}/reporting/resources/report.py` +
     97      `?op=retrieve_report&reportID={{GET[id]}}` +
     98      `&min_count=${expected_blocked_urls.length}`;
     99
     100  let response = await fetch(report_url);
     101  assert_equals(response.status, 200, "Fetching reports failed");
     102
     103  let response_json = await response.json();
     104  let reports = response_json.map(x => x["csp-report"]);
     105
     106  assert_array_equals(
     107      reports.map(x => x["blocked-uri"]).sort(),
     108      expected_blocked_urls.sort(),
     109      "Reports do not match");
     110  reports.forEach(x => {
     111    assert_equals(
     112        x["violated-directive"], "connect-src",
     113        "Violated directive in report does not match");
     114    assert_equals(
     115        x["effective-directive"], "connect-src",
     116        "Effective directive in report does not match");
     117    assert_equals(
     118        x["disposition"], "enforce",
     119        "Effective directive in report does not match");
     120  });
     121}, "Reports match in " + self.location.protocol + " with {{GET[test-name]}}");
    59122
    60123done();
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/support/script-src-allow.sub.js

    r254133 r279838  
    22
    33test(t => {
    4   importScripts("http://{{hosts[alt][]}}:{{ports[http][1]}}/content-security-policy/support/testharness-helper.js");
    5 }, "Cross-origin `importScripts()` not blocked in " + self.location.protocol + self.location.search);
     4  importScripts("https://{{hosts[][www]}}:{{ports[https][1]}}" +
     5                "/content-security-policy/support/testharness-helper.js");
     6}, "Cross-origin `importScripts()` not blocked in " + self.location.protocol +
     7     " withour CSP");
    68
    79test(t => {
    810  assert_equals(2, eval("1+1"));
    911  assert_equals(2, (new Function("return 1+1;"))());
    10 }, "`eval()` not blocked in " + self.location.protocol + self.location.search);
     12}, "`eval()` not blocked in " + self.location.protocol +
     13    " without CSP");
    1114
    1215async_test(t => {
     
    1417
    1518  setTimeout("self.callback();", 1);
    16 }, "`setTimeout([string])` not blocked in " + self.location.protocol + self.location.search);
     19  setTimeout(t.step_func(_ =>
     20      assert_unreached("callback not called.")), 2);
     21}, "`setTimeout([string])` not blocked in " + self.location.protocol +
     22           " without CSP");
    1723
    1824done();
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/support/script-src-self.sub.js

    r263605 r279838  
    22importScripts("{{location[server]}}/content-security-policy/support/testharness-helper.js");
    33
    4 test(t => {
     4let importscripts_url ="https://{{hosts[][www]}}:{{ports[https][1]}}" +
     5    "/content-security-policy/support/var-a.js";
     6
     7promise_test(async t => {
    58  self.a = false;
    69  assert_throws_dom("NetworkError",
    7                     _ => importScripts("http://{{hosts[alt][]}}:{{ports[http][1]}}/content-security-policy/support/var-a.js"),
     10                    _ => importScripts(importscripts_url),
    811                    "importScripts should throw `NetworkError`");
    912  assert_false(self.a);
    10 }, "Cross-origin `importScripts()` blocked in " + self.location.protocol + self.location.search);
     13  return waitUntilCSPEventForURL(t, importscripts_url);
     14}, "Cross-origin `importScripts()` blocked in " + self.location.protocol +
     15             " with {{GET[test-name]}}");
    1116
    12 test(t => {
     17promise_test(t => {
    1318  assert_throws_js(EvalError,
    1419                   _ => eval("1 + 1"),
     
    1823                   _ => new Function("1 + 1"),
    1924                   "`new Function()` should throw 'EvalError'.");
    20 }, "`eval()` blocked in " + self.location.protocol + self.location.search);
     25  return Promise.all([
     26    waitUntilCSPEventForEval(t, 19),
     27    waitUntilCSPEventForEval(t, 23),
     28  ]);
     29}, "`eval()` blocked in " + self.location.protocol +
     30             " with {{GET[test-name]}}");
    2131
    22 async_test(t => {
    23   waitUntilCSPEventForEval(t, 27)
    24     .then(t.step_func_done());
     32promise_test(t => {
     33  self.setTimeoutTest = t;
     34  let result = setTimeout("(self.setTimeoutTest.unreached_func(" +
     35                          "'setTimeout([string]) should not execute.'))()", 1);
     36  assert_equals(result, 0);
     37  return waitUntilCSPEventForEval(t, 34);
     38}, "`setTimeout([string])` blocked in " + self.location.protocol +
     39             " with {{GET[test-name]}}");
    2540
    26   self.setTimeoutTest = t;
    27   var result = setTimeout("(self.setTimeoutTest.unreached_func('setTimeout([string]) should not execute.'))()", 1);
    28   assert_equals(result, 0);
    29 }, "`setTimeout([string])` blocked in " + self.location.protocol + self.location.search);
     41promise_test(async t => {
     42  let report_url = "{{location[server]}}/reporting/resources/report.py" +
     43      "?op=retrieve_report&reportID={{GET[id]}}&min_count=4";
     44
     45  let response = await fetch(report_url);
     46  assert_equals(response.status, 200, "Fetching reports failed");
     47
     48  let response_json = await response.json();
     49  let reports = response_json.map(x => x["csp-report"]);
     50
     51  assert_array_equals(
     52      reports.map(x => x["blocked-uri"]).sort(),
     53      [ importscripts_url, "eval", "eval", "eval" ].sort(),
     54      "Reports do not match");
     55  assert_array_equals(
     56      reports.map(x => x["violated-directive"]).sort(),
     57      [ "script-src-elem", "script-src", "script-src", "script-src" ].sort(),
     58      "Violated directive in report does not match");
     59  assert_array_equals(
     60      reports.map(x => x["effective-directive"]).sort(),
     61      [ "script-src-elem", "script-src", "script-src", "script-src" ].sort(),
     62      "Effective directive in report does not match");
     63  reports.forEach(x => {
     64    assert_equals(
     65        x["disposition"], "enforce",
     66        "Disposition in report does not match");
     67  });
     68}, "Reports are sent for " + self.location.protocol +
     69                  " with {{GET[test-name]}}");
    3070
    3171done();
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/support/w3c-import.log

    r246330 r279838  
    1616List of files:
    1717/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/support/connect-src-allow.sub.js
     18/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/support/connect-src-self-report-only.sub.js
     19/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/support/connect-src-self-report-only.sub.js.sub.headers
    1820/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/support/connect-src-self.sub.js
    1921/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/support/script-src-allow.sub.js
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/w3c-import.log

    r246330 r279838  
    1515------------------------------------------------------------------------
    1616List of files:
    17 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicated-inheritance.html
    18 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicated-script.html
    19 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/shared-inheritance.html
    20 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/shared-script.html
     17/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicatedworker-connect-src.html
     18/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicatedworker-connect-src.html.sub.headers
     19/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicatedworker-report-only.html
     20/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicatedworker-report-only.html.sub.headers
     21/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicatedworker-script-src.html
     22/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicatedworker-script-src.html.sub.headers
     23/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/serviceworker-connect-src.https.sub.html
     24/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/serviceworker-report-only.https.sub.html
     25/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/serviceworker-script-src.https.sub.html
     26/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/sharedworker-connect-src.sub.html
     27/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/sharedworker-report-only.sub.html
     28/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/sharedworker-script-src.sub.html
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/media-src/media-src-7_1_2.sub.html

    r246330 r279838  
    2020          assert_equals(e.blockedURI, mediaURL);
    2121          if (--test_count <= 0) {
    22               t_spv.done(); 
     22              t_spv.done();
    2323          }
    2424      }));
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/media-src/media-src-7_2_2.sub.html

    r246330 r279838  
    2020          assert_equals(e.blockedURI, mediaURL);
    2121          if (--test_count <= 0) {
    22               t_spv.done(); 
     22              t_spv.done();
    2323          }
    2424      }));
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/media-src/media-src-7_3.sub.html

    r254133 r279838  
    33<head>
    44    <title>Video track src attribute must match src list - positive test</title>
    5     <meta http-equiv="Content-Security-Policy" content="script-src * 'unsafe-inline'; media-src 'self' {{hosts[alt][]}}:{{ports[http][0]}};"> 
     5    <meta http-equiv="Content-Security-Policy" content="script-src * 'unsafe-inline'; media-src 'self' {{hosts[alt][]}}:{{ports[http][0]}};">
    66    <script src='/resources/testharness.js'></script>
    77    <script src='/resources/testharnessreport.js'></script>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/media-src/media-src-blocked.sub.html

    r246330 r279838  
    2828          assert_true(e.blockedURI == a_mediaURL || e.blockedURI == v_mediaURL, "Unexpected blockedURI");
    2929          if (--test_count <= 0) {
    30               t_spv.done(); 
     30              t_spv.done();
    3131          }
    3232      }));
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/meta/meta-outside-head.sub.html

    r246330 r279838  
    1919            alert_assert("Fail");
    2020        });
    21     </script>   
     21    </script>
    2222
    2323    <meta http-equiv="Content-Security-Policy" content="script-src 'self'">
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/navigate-to/anchor-navigation-always-allowed.html

    r246330 r279838  
    1212<script>
    1313  var t = async_test("Test that anchor navigation is allowed regardless of the `navigate-to` directive");
    14  
     14
    1515  window.addEventListener('securitypolicyviolation', t.unreached_func("Should not have triggered any violation"));
    16  
     16
    1717  try {
    1818    window.location.hash = "anchor";
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/navigate-to/parent-navigates-child-blocked.html.sub.headers

    r246330 r279838  
    33Pragma: no-cache
    44Set-Cookie: parent-navigates-child-blocked={{$id:uuid()}}; Path=/content-security-policy/navigate-to/
    5 Content-Security-Policy: navigate-to support/wait_for_navigation.html; report-uri ../support/report.py?op=put&reportID={{$id}}
     5Content-Security-Policy: navigate-to support/wait_for_navigation.html; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/navigate-to/support/delayed_frame.py

    r246330 r279838  
    22def main(request, response):
    33    time.sleep(1)
    4     headers = [("Content-Type", "text/html")]
    5     return headers, '''
     4    headers = [(b"Content-Type", b"text/html")]
     5    return headers, u'''
    66<!DOCTYPE html>
    77<head>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/navigate-to/support/form_action_navigation.sub.html

    r246330 r279838  
    2828  }
    2929 } catch(ex) {}
    30  
     30
    3131 document.getElementById('form').submit();
    3232</script>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/navigate-to/support/form_action_navigation.sub.html.sub.headers

    r246330 r279838  
    22Cache-Control: no-store, no-cache, must-revalidate
    33Pragma: no-cache
    4 Content-Security-Policy: {{GET[csp]}}; report-uri /content-security-policy/support/report.py?op=put&reportID={{GET[report_id]}}
     4Content-Security-Policy: {{GET[csp]}}; report-uri /reporting/resources/report.py?op=put&reportID={{GET[report_id]}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/navigate-to/support/href_location_navigation.sub.html.sub.headers

    r246330 r279838  
    22Cache-Control: no-store, no-cache, must-revalidate
    33Pragma: no-cache
    4 Content-Security-Policy: {{GET[csp]}}; report-uri /content-security-policy/support/report.py?op=put&reportID={{GET[report_id]}}
     4Content-Security-Policy: {{GET[csp]}}; report-uri /reporting/resources/report.py?op=put&reportID={{GET[report_id]}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/navigate-to/support/link_click_navigation.sub.html.sub.headers

    r246330 r279838  
    22Cache-Control: no-store, no-cache, must-revalidate
    33Pragma: no-cache
    4 Content-Security-Policy: {{GET[csp]}}; report-uri /content-security-policy/support/report.py?op=put&reportID={{GET[report_id]}}
     4Content-Security-Policy: {{GET[csp]}}; report-uri /reporting/resources/report.py?op=put&reportID={{GET[report_id]}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/navigate-to/support/meta_refresh_navigation.sub.html.sub.headers

    r246330 r279838  
    22Cache-Control: no-store, no-cache, must-revalidate
    33Pragma: no-cache
    4 Content-Security-Policy: {{GET[csp]}}; report-uri /content-security-policy/support/report.py?op=put&reportID={{GET[report_id]}}
     4Content-Security-Policy: {{GET[csp]}}; report-uri /reporting/resources/report.py?op=put&reportID={{GET[report_id]}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/navigate-to/support/navigate_parent.sub.html.sub.headers

    r246330 r279838  
    22Cache-Control: no-store, no-cache, must-revalidate
    33Pragma: no-cache
    4 Content-Security-Policy: {{GET[csp]}}; report-uri /content-security-policy/support/report.py?op=put&reportID={{GET[report_id]}}
     4Content-Security-Policy: {{GET[csp]}}; report-uri /reporting/resources/report.py?op=put&reportID={{GET[report_id]}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/navigate-to/support/redirect_to_post_message_to_frame_owner.py

    r246330 r279838  
    11def main(request, response):
    22    response.status = 302
    3     if "location" in request.GET:
    4         response.headers.set("Location", request.GET["location"])
     3    if b"location" in request.GET:
     4        response.headers.set(b"Location", request.GET[b"location"])
    55    else:
    6         response.headers.set("Location", "post_message_to_frame_owner.html")
     6        response.headers.set(b"Location", b"post_message_to_frame_owner.html")
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/navigate-to/support/spv-test-iframe1.sub.html.sub.headers

    r246330 r279838  
    22Cache-Control: no-store, no-cache, must-revalidate
    33Pragma: no-cache
    4 Content-Security-Policy: navigate-to {{location[server]}}/content-security-policy/navigate-to/support/spv-test-iframe3.sub.html 'unsafe-allow-redirects'; report-uri /content-security-policy/support/report.py?op=put&reportID={{GET[report_id]}}
     4Content-Security-Policy: navigate-to {{location[server]}}/content-security-policy/navigate-to/support/spv-test-iframe3.sub.html 'unsafe-allow-redirects'; report-uri /reporting/resources/report.py?op=put&reportID={{GET[report_id]}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/navigation/javascript-url-navigation-inherits-csp-expected.txt

    r262312 r279838  
    11
     2FAIL Violation report status OK. assert_true: violated-directive value of  "default-src 'none'" did not match frame-src. expected true got false
     3
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/navigation/support/test_csp_self_window.sub.html

    r246330 r279838  
    33<script src="/resources/testharnessreport.js"></script>
    44
     5<span id="escape">{{GET[window_url]}}</span>
     6
    57<script>
    6   var window_url = decodeURIComponent("{{GET[window_url]}}").replace('&lt;', '<').replace('&gt;', '>');
     8  var window_url = document.getElementById("escape").textContent;
    79  window.open(window_url, "_self");
    810</script>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/navigation/support/test_csp_self_window.sub.html.sub.headers

    r246330 r279838  
    44Pragma: no-cache
    55Set-Cookie: {{GET[report_cookie_name]}}={{$id:uuid()}}; Path=/content-security-policy/navigation/
    6 Content-Security-Policy: default-src 'none'; script-src 'self' 'unsafe-inline'; report-uri  ../../support/report.py?op=put&reportID={{$id}}
     6Content-Security-Policy: default-src 'none'; script-src 'self' 'unsafe-inline'; report-uri  /reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/navigation/to-javascript-url-frame-src.html

    r246330 r279838  
    99<script>
    1010  var t = async_test("<iframe src='javascript:...'> not blocked by 'frame-src'");
    11  
     11
    1212  var i = document.createElement('iframe');
    1313  i.src = "javascript:window.top.t.done();";
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/object-src/object-src-no-url-allowed.html

    r246330 r279838  
    55    <script src="/resources/testharness.js"></script>
    66    <script src="/resources/testharnessreport.js"></script>
    7     <!-- Content-Security-Policy: object-src 'self'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}} -->
     7    <!-- Content-Security-Policy: object-src 'self'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} -->
    88</head>
    99
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/object-src/object-src-no-url-allowed.html.sub.headers

    r246330 r279838  
    11Set-Cookie: object-src-no-url-allowed={{$id:uuid()}}; Path=/content-security-policy/object-src/
    2 Content-Security-Policy: object-src 'self'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}}
     2Content-Security-Policy: object-src 'self'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/object-src/object-src-url-allowed.html

    r263605 r279838  
    99        object-src 'self';
    1010        script-src 'self' 'unsafe-inline';
    11         report-uri ../support/report.py?op=put&reportID={{$id}}
     11        report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
    1212    -->
    1313</head>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/object-src/object-src-url-allowed.html.sub.headers

    r246330 r279838  
    11Set-Cookie: object-src-url-allowed={{$id:uuid()}}; Path=/content-security-policy/object-src/
    2 Content-Security-Policy: object-src 'self'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}}
     2Content-Security-Policy: object-src 'self'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/object-src/object-src-url-embed-allowed.html

    r263605 r279838  
    99        object-src 'self';
    1010        script-src 'self' 'unsafe-inline';
    11         report-uri ../support/report.py?op=put&reportID={{$id}}
     11        report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
    1212    -->
    1313</head>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/object-src/object-src-url-embed-allowed.html.sub.headers

    r246330 r279838  
    11Set-Cookie: object-src-url-embed-allowed={{$id:uuid()}}; Path=/content-security-policy/object-src/
    2 Content-Security-Policy: object-src 'self'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}}
     2Content-Security-Policy: object-src 'self'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/object-src/object-src-url-redirect-allowed.html

    r246330 r279838  
    55    <script src="/resources/testharness.js"></script>
    66    <script src="/resources/testharnessreport.js"></script>
    7     <!-- Content-Security-Policy: object-src 'self'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}} -->
     7    <!-- Content-Security-Policy: object-src 'self'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} -->
    88</head>
    99
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/object-src/object-src-url-redirect-allowed.html.sub.headers

    r246330 r279838  
    11Set-Cookie: object-src-url-redirect-allowed={{$id:uuid()}}; Path=/content-security-policy/object-src/
    2 Content-Security-Policy: object-src 'self'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}}
     2Content-Security-Policy: object-src 'self'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/plugin-types/w3c-import.log

    r246330 r279838  
    1515------------------------------------------------------------------------
    1616List of files:
    17 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-empty.sub.html
    18 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-mismatched-data.html
    19 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-mismatched-url.html
    20 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-notype-data.html
    21 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-notype-url.html
    22 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-nourl-allowed.html
    23 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-nourl-allowed.html.sub.headers
    24 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugintypes-nourl-blocked.html
     17/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugin-types-ignored.html
     18/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/plugin-types/plugin-types-ignored.html.sub.headers
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-allowed.html

    r246330 r279838  
    1111                            'file-prefetch-allowed.html');
    1212      win.addEventListener('load', function () {
    13         // Cache control headers are added,since they are needed 
     13        // Cache control headers are added,since they are needed
    1414        // to enable prefetching.
    1515        let url = '/content-security-policy/support/pass.png' +
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-header-allowed.html

    r246330 r279838  
    1616
    1717      waitUntilResourceDownloaded(url)
    18         .then(t.step_func_done()); 
     18        .then(t.step_func_done());
    1919    }, 'Prefetch via `Link` header succeeds when allowed by prefetch-src');
    2020  </script>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-header-blocked.html

    r246330 r279838  
    22<html>
    33<head>
    4   <meta http-equiv="Content-Security-Policy" content="prefetch-src 'none'">
     4  <!-- Headers:
     5    Content-Security-Policy: prefetch-src 'none'
     6    Link: </content-security-policy/support/fail.png>;rel=prefetch
     7  -->
    58  <script src='/resources/testharness.js'></script>
    69  <script src='/resources/testharnessreport.js'></script>
     
    1316        .then(t.step_func_done(e => {
    1417          assert_equals(e.violatedDirective, 'prefetch-src');
     18
     19          // This assert verifies both that the resource wasn't downloaded
     20          // when prefetched via `Link` on both this document itself, and
     21          // on the stylesheet subresource below.
    1522          assert_resource_not_downloaded(t, url);
    1623        }));
    1724
    18       // Load a stylesheet that tries to trigger a prefetch:
    19       let link = document.createElement('link');
    20       link.rel = 'stylesheet';
    21       link.href = '/content-security-policy/support/prefetch-subresource.css';
    22       document.head.appendChild(link);
    23     }, 'Prefetch via `Link` header succeeds when allowed by prefetch-src');
     25        // Load a stylesheet that tries to trigger a prefetch:
     26        let link = document.createElement('link');
     27        link.rel = 'stylesheet';
     28        link.href = '/content-security-policy/support/prefetch-subresource.css';
     29        document.head.appendChild(link);
     30    }, 'Prefetch via `Link` header blocked when allowed by prefetch-src');
    2431  </script>
    2532</head>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/prefetch-src/w3c-import.log

    r246330 r279838  
    1616List of files:
    1717/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-allowed.html
     18/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-blocked-by-default.html
    1819/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-blocked.html
    1920/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-header-allowed.html
    2021/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-header-allowed.html.headers
     22/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-header-blocked-by-default.html
     23/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-header-blocked-by-default.html.headers
    2124/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-header-blocked.html
     25/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-header-blocked.html.headers
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-doesnt-send-reports-without-violation.https.sub.html.sub.headers

    r246330 r279838  
    44Pragma: no-cache
    55Set-Cookie: reporting-api-doesnt-send-reports-without-violation={{$id:uuid()}}; Path=/content-security-policy/reporting-api
    6 Report-To: { "group": "csp-group", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/content-security-policy/support/report.py?op=put&reportID={{$id}}" }] }
     6Report-To: { "group": "csp-group", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/reporting/resources/report.py?op=put&reportID={{$id}}" }] }
    77Content-Security-Policy: script-src 'self' 'unsafe-inline'; img-src 'self'; report-to csp-group
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-report-only-sends-reports-on-violation.https.sub.html.sub.headers

    r246330 r279838  
    44Pragma: no-cache
    55Set-Cookie: reporting-api-report-only-sends-reports-on-violation={{$id:uuid()}}; Path=/content-security-policy/reporting-api
    6 Report-To: { "group": "csp-group", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/content-security-policy/support/report.py?op=put&reportID={{$id}}" }] }
     6Report-To: { "group": "csp-group", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/reporting/resources/report.py?op=put&reportID={{$id}}" }] }
    77Content-Security-Policy-Report-Only: script-src 'self' 'unsafe-inline'; img-src 'none'; report-to csp-group
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-report-to-only-sends-reports-to-first-endpoint.https.sub.html.sub.headers

    r263605 r279838  
    55Set-Cookie: reporting-api-report-to-only-sends-reports-to-first-endpoint={{$id:uuid()}}; Path=/content-security-policy/reporting-api
    66Content-Security-Policy: script-src 'self' 'unsafe-inline'; img-src 'none'; report-to csp-group csp-group-2
    7 Report-To: { "group": "csp-group", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/content-security-policy/support/report.py?op=put&reportID={{uuid()}}" }] }, { "group": "csp-group-2", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/content-security-policy/support/report.py?op=put&reportID={{$id}}" }] }
     7Report-To: { "group": "csp-group", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/reporting/resources/report.py?op=put&reportID={{uuid()}}" }] }, { "group": "csp-group-2", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/reporting/resources/report.py?op=put&reportID={{$id}}" }] }
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-report-to-overrides-report-uri-1.https.sub.html.sub.headers

    r246330 r279838  
    44Pragma: no-cache
    55Set-Cookie: reporting-api-report-to-overrides-report-uri-1={{$id:uuid()}}; Path=/content-security-policy/reporting-api
    6 Content-Security-Policy: script-src 'self' 'unsafe-inline'; img-src 'none'; report-uri "/content-security-policy/support/report.py?op=put&reportID={{$id}}"; report-to csp-group
    7 Report-To: { "group": "csp-group", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/content-security-policy/support/report.py?op=put&reportID={{$id:uuid()}}" }] }
     6Content-Security-Policy: script-src 'self' 'unsafe-inline'; img-src 'none'; report-uri "/reporting/resources/report.py?op=put&reportID={{$id}}"; report-to csp-group
     7Report-To: { "group": "csp-group", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/reporting/resources/report.py?op=put&reportID={{$id:uuid()}}" }] }
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-report-to-overrides-report-uri-2.https.sub.html.sub.headers

    r246330 r279838  
    44Pragma: no-cache
    55Set-Cookie: reporting-api-report-to-overrides-report-uri-2={{$id:uuid()}}; Path=/content-security-policy/reporting-api
    6 Content-Security-Policy: script-src 'self' 'unsafe-inline'; img-src 'none'; report-to csp-group; report-uri "/content-security-policy/support/report.py?op=put&reportID={{$id}}"
    7 Report-To: { "group": "csp-group", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/content-security-policy/support/report.py?op=put&reportID={{$id:uuid()}}" }] }
     6Content-Security-Policy: script-src 'self' 'unsafe-inline'; img-src 'none'; report-to csp-group; report-uri "/reporting/resources/report.py?op=put&reportID={{$id}}"
     7Report-To: { "group": "csp-group", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/reporting/resources/report.py?op=put&reportID={{$id:uuid()}}" }] }
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-sends-reports-on-violation.https.sub.html

    r263605 r279838  
    3737          assert_equals(reports[0].body.sample, "");
    3838          assert_equals(reports[0].body.disposition, "enforce");
    39           assert_equals(reports[0].body.statusCode, 0);
     39          assert_equals(reports[0].body.statusCode, 200);
    4040          assert_equals(reports[0].body.lineNumber, 53);
    4141          assert_equals(reports[0].body.columnNumber, 0);
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-sends-reports-on-violation.https.sub.html.sub.headers

    r246330 r279838  
    44Pragma: no-cache
    55Set-Cookie: reporting-api-sends-reports-on-violation={{$id:uuid()}}; Path=/content-security-policy/reporting-api
    6 Report-To: { "group": "csp-group", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/content-security-policy/support/report.py?op=put&reportID={{$id}}" }] }
     6Report-To: { "group": "csp-group", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/reporting/resources/report.py?op=put&reportID={{$id}}" }] }
    77Content-Security-Policy: script-src 'self' 'unsafe-inline'; img-src 'none'; report-to csp-group
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-works-on-frame-src.https.sub.html.sub.headers

    r246330 r279838  
    33Pragma: no-cache
    44Set-Cookie: reporting-api-works-on-frame-src={{$id:uuid()}}; Path=/content-security-policy/reporting-api
    5 Report-To: { "group": "csp-group", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/content-security-policy/support/report.py?op=put&reportID={{$id}}" }] }
     5Report-To: { "group": "csp-group", "max_age": 10886400, "endpoints": [{ "url": "https://{{host}}:{{ports[https][0]}}/reporting/resources/report.py?op=put&reportID={{$id}}" }] }
    66Content-Security-Policy: script-src 'self' 'unsafe-inline'; frame-src 'none'; report-to csp-group
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/w3c-import.log

    r263605 r279838  
    1515------------------------------------------------------------------------
    1616List of files:
     17/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/report-to-directive-allowed-in-meta.https.sub.html
     18/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/report-to-directive-allowed-in-meta.https.sub.html.sub.headers
    1719/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-doesnt-send-reports-without-violation.https.sub.html
    1820/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-doesnt-send-reports-without-violation.https.sub.html.sub.headers
     
    2729/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-sends-reports-on-violation.https.sub.html
    2830/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-sends-reports-on-violation.https.sub.html.sub.headers
     31/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-works-on-frame-ancestors.https.sub.html
     32/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-works-on-frame-ancestors.https.sub.html.sub.headers
    2933/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-works-on-frame-src.https.sub.html
    3034/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting-api/reporting-api-works-on-frame-src.https.sub.html.sub.headers
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/multiple-report-policies.html

    r246330 r279838  
    66    <title>When multiple report-uri endpoints for multiple policies are specified, each gets a report</title>
    77    <!-- CSP headers
    8 Content-Security-Policy-Report-Only: img-src http://* https://*; default-src 'self'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}}
     8Content-Security-Policy-Report-Only: img-src http://* https://*; default-src 'self'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
    99
    10 Content-Security-Policy-Report-Only: img-src http://*; default-src 'self'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}}
     10Content-Security-Policy-Report-Only: img-src http://*; default-src 'self'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
    1111-->
    1212</head>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/multiple-report-policies.html.sub.headers

    r246330 r279838  
    44Pragma: no-cache
    55Set-Cookie: multiple-report-policies={{$id:uuid()}}; Path=/content-security-policy/reporting/
    6 Content-Security-Policy-Report-Only: img-src http://* https://*; default-src 'self'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}}
     6Content-Security-Policy-Report-Only: img-src http://* https://*; default-src 'self'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
    77Set-Cookie: multiple-report-policies-2={{$id:uuid()}}; Path=/content-security-policy/reporting/
    8 Content-Security-Policy-Report-Only: img-src http://*; default-src 'self'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}}
     8Content-Security-Policy-Report-Only: img-src http://*; default-src 'self'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/post-redirect-stacktrace.https.html

    r263605 r279838  
    1414
    1515const blank_path = "/common/blank.html"
    16 const redirect = url => 
     16const redirect = url =>
    1717  `/content-security-policy/reporting/support/redirect-throw-function.sub.py?token=${token()}`;
    1818
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-and-enforce.html

    r246330 r279838  
    88Content-Security-Policy: img-src 'none'; style-src *; script-src 'self' 'unsafe-inline'
    99
    10 Content-Security-Policy-Report-Only: img-src *; style-src 'none'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}}
     10Content-Security-Policy-Report-Only: img-src *; style-src 'none'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
    1111-->
    1212</head>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-and-enforce.html.sub.headers

    r246330 r279838  
    55Set-Cookie: report-and-enforce={{$id:uuid()}}; Path=/content-security-policy/reporting/
    66Content-Security-Policy: img-src 'none'; style-src *; script-src 'self' 'unsafe-inline'
    7 Content-Security-Policy-Report-Only: img-src *; style-src 'none'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}}
     7Content-Security-Policy-Report-Only: img-src *; style-src 'none'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-blocked-data-uri.html

    r246330 r279838  
    66    <title>Data-uri images are reported correctly</title>
    77    <!-- CSP headers
    8 Content-Security-Policy: img-src 'none'; report-uri ../support/report.py?op=put&reportID={{$id}}
     8Content-Security-Policy: img-src 'none'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
    99-->
    1010</head>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-blocked-data-uri.html.sub.headers

    r246330 r279838  
    44Pragma: no-cache
    55Set-Cookie: report-blocked-data-uri={{$id:uuid()}}; Path=/content-security-policy/reporting/
    6 Content-Security-Policy: img-src 'none'; report-uri ../support/report.py?op=put&reportID={{$id}}
     6Content-Security-Policy: img-src 'none'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-blocked-uri-cross-origin.sub.html

    r246330 r279838  
    77    <!-- CSP headers
    88Content-Security-Policy: script-src 'self' 'unsafe-inline'
    9 Content-Security-Policy-Report-Only: img-src 'none'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID=$id
     9Content-Security-Policy-Report-Only: img-src 'none'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID=$id
    1010-->
    1111</head>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-blocked-uri-cross-origin.sub.html.sub.headers

    r246330 r279838  
    55Set-Cookie: report-blocked-uri-cross-origin={{$id:uuid()}}; Path=/content-security-policy/reporting/
    66Content-Security-Policy: script-src 'self' 'unsafe-inline'
    7 Content-Security-Policy-Report-Only: img-src 'none'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}}
     7Content-Security-Policy-Report-Only: img-src 'none'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-blocked-uri.html

    r246330 r279838  
    77    <!-- CSP headers
    88Content-Security-Policy: script-src 'self' 'unsafe-inline'
    9 Content-Security-Policy-Report-Only: img-src 'none'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}}
     9Content-Security-Policy-Report-Only: img-src 'none'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
    1010-->
    1111</head>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-blocked-uri.html.sub.headers

    r246330 r279838  
    55Set-Cookie: report-blocked-uri={{$id:uuid()}}; Path=/content-security-policy/reporting/
    66Content-Security-Policy: script-src 'self' 'unsafe-inline'
    7 Content-Security-Policy-Report-Only: img-src 'none'; script-src 'self' 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}}
     7Content-Security-Policy-Report-Only: img-src 'none'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-cross-origin-no-cookies.sub.html

    r254133 r279838  
    77    <script src="/resources/testharnessreport.js"></script>
    88    <!-- CSP headers
    9          Content-Security-Policy: script-src 'unsafe-inline' 'self'; img-src 'none'; report-uri http://{{domains[www1]}}:{{ports[http][0]}}/content-security-policy/support/report.py?op=put&reportID=$id
     9         Content-Security-Policy: script-src 'unsafe-inline' 'self'; img-src 'none'; report-uri http://{{domains[www1]}}:{{ports[http][0]}}/reporting/resources/report.py?op=put&reportID=$id
    1010         -->
    1111</head>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-cross-origin-no-cookies.sub.html.sub.headers

    r246330 r279838  
    44Pragma: no-cache
    55Set-Cookie: report-cross-origin-no-cookies={{$id:uuid()}}; Path=/content-security-policy/reporting/
    6 Content-Security-Policy: script-src 'unsafe-inline' 'self'; img-src 'none'; report-uri http://{{domains[www1]}}:{{ports[http][0]}}/content-security-policy/support/report.py?op=put&reportID={{$id}}
     6Content-Security-Policy: script-src 'unsafe-inline' 'self'; img-src 'none'; report-uri http://{{domains[www1]}}:{{ports[http][0]}}/reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-multiple-violations-01.html

    r246330 r279838  
    66    <title>Test multiple violations cause multiple reports</title>
    77    <!-- CSP headers
    8          Content-Security-Policy-Report-Only: script-src 'unsafe-inline' 'self'; img-src 'none'; report-uri ../support/report.py?op=put&reportID={{$id}}
     8         Content-Security-Policy-Report-Only: script-src 'unsafe-inline' 'self'; img-src 'none'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
    99         -->
    1010</head>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-multiple-violations-01.html.sub.headers

    r246330 r279838  
    44Pragma: no-cache
    55Set-Cookie: report-multiple-violations-01={{$id:uuid()}}; Path=/content-security-policy/reporting/
    6 Content-Security-Policy-Report-Only: script-src 'unsafe-inline' 'self'; img-src 'none'; report-uri ../support/report.py?op=put&reportID={{$id}}
     6Content-Security-Policy-Report-Only: script-src 'unsafe-inline' 'self'; img-src 'none'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-multiple-violations-02.html

    r246330 r279838  
    77        if and only if the violations are distinct.</title>
    88    <!-- CSP headers
    9          Content-Security-Policy-Report-Only: script-src 'unsafe-inline' 'self'; report-uri ../support/report.py?op=put&reportID={{$id}}
     9         Content-Security-Policy-Report-Only: script-src 'unsafe-inline' 'self'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
    1010         -->
    1111</head>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-multiple-violations-02.html.sub.headers

    r246330 r279838  
    44Pragma: no-cache
    55Set-Cookie: report-multiple-violations-02={{$id:uuid()}}; Path=/content-security-policy/reporting/
    6 Content-Security-Policy-Report-Only: script-src 'unsafe-inline' 'self'; report-uri ../support/report.py?op=put&reportID={{$id}}
     6Content-Security-Policy-Report-Only: script-src 'unsafe-inline' 'self'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-only-in-meta.sub.html

    r254133 r279838  
    1010         -->
    1111    <!-- since we try to set the report-uri in the meta tag, we have to set the cookie with the reportID in here instead of in the headers file -->
    12     <meta http-equiv="Content-Security-Policy-Report-Only" content="img-src 'none'; report-uri ../support/report.py?op=put&reportID={{$id:uuid()}}">
     12    <meta http-equiv="Content-Security-Policy-Report-Only" content="img-src 'none'; report-uri /reporting/resources/report.py?op=put&reportID={{$id:uuid()}}">
    1313</head>
    1414<body>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-only-unsafe-eval.html

    r254133 r279838  
    55    <script nonce='abc' src="/resources/testharnessreport.js"></script>
    66    <!-- CSP headers
    7 Content-Security-Policy-Report-Only: script-src 'unsafe-inline' 'nonce-abc'; report-uri ../support/report.py?op=put&reportID={{$id}}
     7Content-Security-Policy-Report-Only: script-src 'unsafe-inline' 'nonce-abc'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
    88-->
    99</head>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-only-unsafe-eval.html.sub.headers

    r254133 r279838  
    22Pragma: no-cache
    33Set-Cookie: report-only-unsafe-eval={{$id:uuid()}}; Path=/content-security-policy/reporting/
    4 Content-Security-Policy-Report-Only: script-src 'unsafe-inline' 'nonce-abc'; report-uri ../support/report.py?op=put&reportID={{$id}}
     4Content-Security-Policy-Report-Only: script-src 'unsafe-inline' 'nonce-abc'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-original-url-on-mixed-content-frame.https.sub.html.sub.headers

    r263605 r279838  
    44Pragma: no-cache
    55Set-Cookie: report-original-url-on-mixed-content-frame={{$id:uuid()}}; Path=/content-security-policy/reporting/
    6 Content-Security-Policy: block-all-mixed-content; report-uri ../support/report.py?op=put&reportID={{$id}}
     6Content-Security-Policy: block-all-mixed-content; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-original-url.sub.html

    r263605 r279838  
    55  <script src="/resources/testharnessreport.js"></script>
    66  <!-- CSP headers
    7        Content-Security-Policy: img-src {{location[scheme]}}://{{domains[www1]}}:{{ports[http][0]}}; script-src 'unsafe-inline' 'self'; report-uri ../support/report.py?op=put&reportID=$id
     7       Content-Security-Policy: img-src {{location[scheme]}}://{{domains[www1]}}:{{ports[http][0]}}; script-src 'unsafe-inline' 'self'; report-uri /reporting/resources/report.py?op=put&reportID=$id
    88       -->
    99</head>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-original-url.sub.html.sub.headers

    r246330 r279838  
    44Pragma: no-cache
    55Set-Cookie: report-original-url={{$id:uuid()}}; Path=/content-security-policy/reporting/
    6 Content-Security-Policy: img-src {{location[scheme]}}://{{domains[www1]}}:{{ports[http][0]}}; script-src 'unsafe-inline' 'self'; report-uri ../support/report.py?op=put&reportID={{$id}}
     6Content-Security-Policy: img-src {{location[scheme]}}://{{domains[www1]}}:{{ports[http][0]}}; script-src 'unsafe-inline' 'self'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-same-origin-with-cookies.html

    r246330 r279838  
    66    <title>Cookies are sent on same origin violation reports</title>
    77    <!-- CSP headers
    8          Content-Security-Policy: script-src 'unsafe-inline' 'self'; img-src 'none'; report-uri /content-security-policy/support/report.py?op=put&reportID={{$id}}
     8         Content-Security-Policy: script-src 'unsafe-inline' 'self'; img-src 'none'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
    99         -->
    1010</head>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-same-origin-with-cookies.html.sub.headers

    r246330 r279838  
    44Pragma: no-cache
    55Set-Cookie: report-same-origin-with-cookies={{$id:uuid()}}; Path=/content-security-policy/reporting/
    6 Content-Security-Policy: script-src 'unsafe-inline' 'self'; img-src 'none'; report-uri /content-security-policy/support/report.py?op=put&reportID={{$id}}
     6Content-Security-Policy: script-src 'unsafe-inline' 'self'; img-src 'none'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-effective-directive.html

    r246330 r279838  
    66    <title>Violation report is sent if violation occurs.</title>
    77    <!-- CSP headers
    8          Content-Security-Policy: default-src 'self'; report-uri ../support/report.py?op=put&reportID={{$id}}
     8         Content-Security-Policy: default-src 'self'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
    99         -->
    1010</head>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-effective-directive.html.sub.headers

    r246330 r279838  
    44Pragma: no-cache
    55Set-Cookie: report-uri-effective-directive={{$id:uuid()}}; Path=/content-security-policy/reporting/
    6 Content-Security-Policy: default-src 'self'; report-uri ../support/report.py?op=put&reportID={{$id}}
     6Content-Security-Policy: default-src 'self'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-from-inline-javascript.html

    r246330 r279838  
    66    <title>Violation report is sent from inline javascript.</title>
    77    <!-- CSP headers
    8          Content-Security-Policy: img-src 'none'; report-uri ../support/report.py?op=put&reportID={{$id}}
     8         Content-Security-Policy: img-src 'none'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
    99         -->
    1010</head>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-from-inline-javascript.html.sub.headers

    r246330 r279838  
    44Pragma: no-cache
    55Set-Cookie: report-uri-from-inline-javascript={{$id:uuid()}}; Path=/content-security-policy/reporting/
    6 Content-Security-Policy: img-src 'none'; report-uri ../support/report.py?op=put&reportID={{$id}}
     6Content-Security-Policy: img-src 'none'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-from-javascript.html

    r246330 r279838  
    66    <title>Violation report is sent from javascript resource.</title>
    77    <!-- CSP headers
    8          Content-Security-Policy: img-src 'none'; report-uri ../support/report.py?op=put&reportID={{$id}}
     8         Content-Security-Policy: img-src 'none'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
    99         -->
    1010</head>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-from-javascript.html.sub.headers

    r246330 r279838  
    44Pragma: no-cache
    55Set-Cookie: report-uri-from-javascript={{$id:uuid()}}; Path=/content-security-policy/reporting/
    6 Content-Security-Policy: img-src 'none'; report-uri ../support/report.py?op=put&reportID={{$id}}
     6Content-Security-Policy: img-src 'none'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-multiple-reversed.html

    r246330 r279838  
    66    <title>Content-Security-Policy-Report-Only violation report is sent even when resource is blocked by actual policy.</title>
    77    <!-- CSP headers
    8          Content-Security-Policy-Report-Only: img-src http://*; report-uri ../support/report.py?op=put&reportID={{$id}}
     8         Content-Security-Policy-Report-Only: img-src http://*; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
    99         Content-Security-Policy: img-src http://*
    1010         -->
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-multiple-reversed.html.sub.headers

    r246330 r279838  
    44Pragma: no-cache
    55Set-Cookie: report-uri-multiple-reversed={{$id:uuid()}}; Path=/content-security-policy/reporting/
    6 Content-Security-Policy-Report-Only: img-src http://*; report-uri ../support/report.py?op=put&reportID={{$id}}
     6Content-Security-Policy-Report-Only: img-src http://*; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
    77Content-Security-Policy: img-src http://*
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-multiple.html

    r246330 r279838  
    77    <!-- CSP headers
    88         Content-Security-Policy: img-src http://*
    9          Content-Security-Policy-Report-Only: img-src http://*; report-uri ../support/report.py?op=put&reportID={{$id}}
     9         Content-Security-Policy-Report-Only: img-src http://*; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
    1010      -->
    1111</head>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-multiple.html.sub.headers

    r246330 r279838  
    55Set-Cookie: report-uri-multiple={{$id:uuid()}}; Path=/content-security-policy/reporting/
    66Content-Security-Policy: img-src http://*
    7 Content-Security-Policy-Report-Only: img-src http://*; report-uri ../support/report.py?op=put&reportID={{$id}}
     7Content-Security-Policy-Report-Only: img-src http://*; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-scheme-relative.html

    r246330 r279838  
    66    <title>Relative scheme URIs are accepted as the report-uri.</title>
    77    <!-- CSP headers
    8          Content-Security-Policy: script-src 'self'; report-uri //{{location[host]}}/content-security-policy/support/report.py?op=put&reportID={{$id}}
     8         Content-Security-Policy: script-src 'self'; report-uri //{{location[host]}}/reporting/resources/report.py?op=put&reportID={{$id}}
    99         -->
    1010</head>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-uri-scheme-relative.html.sub.headers

    r246330 r279838  
    44Pragma: no-cache
    55Set-Cookie: report-uri-scheme-relative={{$id:uuid()}}; Path=/content-security-policy/reporting/
    6 Content-Security-Policy: script-src 'self'; report-uri //{{location[host]}}/content-security-policy/support/report.py?op=put&reportID={{$id}}
     6Content-Security-Policy: script-src 'self'; report-uri //{{location[host]}}/reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/support/generate-csp-report.html.sub.headers

    r246330 r279838  
    44Pragma: no-cache
    55Set-Cookie: generate-csp-report={{$id:uuid()}}; Path=/content-security-policy/reporting/
    6 Content-Security-Policy: script-src 'self' 'nonce-abc'; report-uri ../../support/report.py?op=put&reportID={{$id}}
     6Content-Security-Policy: script-src 'self' 'nonce-abc'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/support/w3c-import.log

    r263605 r279838  
    1717/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/support/generate-csp-report.html
    1818/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/support/generate-csp-report.html.sub.headers
     19/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/support/not-embeddable-frame.py
    1920/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/support/redirect-throw-function.sub.py
    2021/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/support/set-cookie.py
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/w3c-import.log

    r263605 r279838  
    3030/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-cross-origin-no-cookies.sub.html
    3131/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-cross-origin-no-cookies.sub.html.sub.headers
     32/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-frame-ancestors-with-x-frame-options.sub.html
     33/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-frame-ancestors.sub.html
    3234/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-multiple-violations-01.html
    3335/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/reporting/report-multiple-violations-01.html.sub.headers
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/support/w3c-import.log

    r246330 r279838  
    1515------------------------------------------------------------------------
    1616List of files:
     17/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/support/empty.html
     18/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/support/post-origin-on-load-worker.js
    1719/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/support/sandboxed-data-iframe.sub.html
    1820/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/support/sandboxed-data-iframe.sub.html.sub.headers
     
    2224/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/support/sandboxed-post-property-to-opener.html
    2325/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/support/sandboxed-post-property-to-opener.html.sub.headers
     26/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/support/sandboxed-service-worker.js
     27/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/support/sandboxed-service-worker.js.headers
     28/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/support/sandboxed-shared-worker.js
     29/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/support/sandboxed-shared-worker.js.headers
    2430/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/support/unsandboxed-post-property-to-opener.html
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/w3c-import.log

    r246330 r279838  
    1616List of files:
    1717/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/iframe-inside-csp.sub.html
     18/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/meta-element.sub.html
    1819/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/sandbox-allow-scripts-subframe.sub.html
    1920/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/sandbox-allow-scripts.sub.html
    2021/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/sandbox-empty-subframe.sub.html
    2122/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/sandbox-empty.sub.html
     23/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/service-worker-sandbox.https.html
     24/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/shared-worker-sandbox.html
    2225/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/window-reuse-sandboxed.html
    2326/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/sandbox/window-reuse-unsandboxed.html
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/10_1_support_2.js

    r246330 r279838  
    22            assert_true(dataScriptRan, "data script ran");
    33        }, "Verify that data: as script src runs with this policy");
    4        
     4
    55t_spv.done();
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/eval-allowed-in-report-only-mode-and-sends-report-expected.txt

    r267651 r279838  
    11
    22PASS Eval is allowed because the CSP is report-only
    3 PASS Violation report status OK.
     3FAIL Violation report status OK. undefined is not an object (evaluating 'data[0]["body"]')
    44
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/eval-allowed-in-report-only-mode-and-sends-report.html

    r246330 r279838  
    33  <script src="/resources/testharness.js"></script>
    44  <script src="/resources/testharnessreport.js"></script>
    5   <!-- Content-Security-Policy-Report-Only: script-src 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}} -->
     5  <!-- Content-Security-Policy-Report-Only: script-src 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}} -->
    66</head>
    77<body>
     
    1515  </script>
    1616
    17   <script async defer src="../support/checkReport.sub.js?reportField=violated-directive&reportValue=script-src%20%27unsafe-inline%27"></script>
     17  <script async defer src="../support/checkReport.sub.js?reportField=blocked-uri&reportValue=eval"></script>
    1818</body>
    1919</html>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/eval-allowed-in-report-only-mode-and-sends-report.html.sub.headers

    r246330 r279838  
    11Set-Cookie: eval-allowed-in-report-only-mode-and-sends-report={{$id:uuid()}}; Path=/content-security-policy/script-src
    2 Content-Security-Policy-Report-Only: script-src 'unsafe-inline'; report-uri ../support/report.py?op=put&reportID={{$id}}
     2Content-Security-Policy-Report-Only: script-src 'unsafe-inline' 'self'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/injected-inline-script-blocked.sub-expected.txt

    r246330 r279838  
    11
    2 FAIL Expecting logs: ["violated-directive=script-src-elem",] assert_unreached: Logging timeout, expected logs violated-directive=script-src-elem not sent. Reached unreachable code
     2FAIL Expecting logs: ["violated-directive=script-src-elem","blocked-uri=inline"] assert_unreached: Logging timeout, expected logs violated-directive=script-src-elem,blocked-uri=inline not sent. Reached unreachable code
    33
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/injected-inline-script-blocked.sub.html

    r246330 r279838  
    88    <script nonce='abc' src="/resources/testharness.js"></script>
    99    <script nonce='abc' src="/resources/testharnessreport.js"></script>
    10     <script nonce='abc' src='../support/logTest.sub.js?logs=["violated-directive=script-src-elem",]'></script>
     10    <script nonce='abc' src='../support/logTest.sub.js?logs=["violated-directive=script-src-elem","blocked-uri=inline"]'></script>
    1111    <script nonce='abc' src='../support/alertAssert.sub.js?alerts=[]'></script>
    1212</head>
     
    1616       window.addEventListener('securitypolicyviolation', function(e) {
    1717            log("violated-directive=" + e.violatedDirective);
     18            log("blocked-uri=" + e.blockedURI);
    1819        });
    1920    </script>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/javascript-window-open-blocked.html.sub.headers

    r246330 r279838  
    44Pragma: no-cache
    55Set-Cookie: javascript-window-open-blocked={{$id:uuid()}}; Path=/content-security-policy/script-src/
    6 Content-Security-Policy: script-src 'nonce-abc'; report-uri  ../support/report.py?op=put&reportID={{$id}}
     6Content-Security-Policy: script-src 'nonce-abc'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-1_10.html

    r246330 r279838  
    1414        var dataScriptRan = false;
    1515        var t_spv = async_test("Test that securitypolicyviolation event is fired");
    16        
     16
    1717        window.addEventListener("securitypolicyviolation", t_spv.step_func_done(function(e) {
    18             assert_equals(e.violatedDirective, "script-src");
     18            assert_equals(e.violatedDirective, "script-src-elem");
    1919        }));
    2020    </script>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-1_4.html

    r263605 r279838  
    1313        <script>
    1414        var t_spv = async_test("Test that securitypolicyviolation event is fired");
    15        
     15
    1616        window.addEventListener("securitypolicyviolation", t_spv.step_func_done(function(e) {
    1717            assert_equals(e.violatedDirective, "script-src");
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-1_4_1.html

    r246330 r279838  
    33<head>
    44    <title>setTimeout() and setInterval() should not run without 'unsafe-eval' script-src directive.</title>
    5     <meta http-equiv="Content-Security-Policy" content="script-src 'self' 'unsafe-inline';"> 
     5    <meta http-equiv="Content-Security-Policy" content="script-src 'self' 'unsafe-inline';">
    66    <script src='/resources/testharness.js'></script>
    77    <script src='/resources/testharnessreport.js'></script>
     
    1616        var t_spv = async_test("Test that securitypolicyviolation event is fired");
    1717        var test_count = 2;
    18        
     18
    1919        window.addEventListener("securitypolicyviolation", t_spv.step_func_done(function(e) {
    2020            assert_equals(e.violatedDirective, "script-src");
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-1_4_2.html

    r263605 r279838  
    1313        <script>
    1414            var t_spv = async_test("Test that securitypolicyviolation event is fired");
    15        
     15
    1616        window.addEventListener("securitypolicyviolation", t_spv.step_func_done(function(e) {
    1717            assert_equals(e.violatedDirective, "script-src");
    1818        }));
    19            
     19
    2020
    2121        test(function() {
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_eval.html

    r263605 r279838  
    2121                assert_false(evalScriptRan);
    2222                assert_equals(e.effectiveDirective, 'script-src');
     23                assert_equals(e.blockedURI, 'eval');
    2324            }));
    2425
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_hashes.html

    r246330 r279838  
    77    <script src='/resources/testharnessreport.js' nonce='dummy'></script>
    88
    9     <!-- CSP served: script-src 'strict-dynamic' 'nonce-dummy' 'sha256-yU6Q7nD1TCBB9JvY06iIJ8ONLOPU4g8ml5JCDgXkv+M=' 'sha256-IFt1v6itHgqlrtInbPm/y7qyWcAlDbPgZM+92C5EZ5o=' -->
     9    <!-- CSP served: script-src 'strict-dynamic' 'nonce-dummy' 'sha256-yU6Q7nD1TCBB9JvY06iIJ8ONLOPU4g8ml5JCDgXkv+M=' 'sha256-EEoi70frWHkGFhK51NVIJkXpq72aPxSCNZEow37ZmRA=' -->
    1010</head>
    1111
     
    1717        var hashScriptRan = false;
    1818        window.addEventListener('securitypolicyviolation', function(e) {
    19             assert_unreached('No CSP violation report has fired.');
     19            assert_unreached('CSP violation reports should not fire.');
    2020        });
    2121    </script>
    2222
    23     <!-- Hash: 'sha256-yU6Q7nD1TCBB9JvY06iIJ8ONLOPU4g8ml5JCDgXkv+M=' -->
     23    <!-- Hash: 'sha256-EEoi70frWHkGFhK51NVIJkXpq72aPxSCNZEow37ZmRA=' -->
    2424    <script>
    2525        hashScriptRan = true;
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_hashes.html.headers

    r246330 r279838  
    33Cache-Control: post-check=0, pre-check=0, false
    44Pragma: no-cache
    5 Content-Security-Policy: script-src 'strict-dynamic' 'nonce-dummy' 'sha256-yU6Q7nD1TCBB9JvY06iIJ8ONLOPU4g8ml5JCDgXkv+M=' 'sha256-IFt1v6itHgqlrtInbPm/y7qyWcAlDbPgZM+92C5EZ5o='
     5Content-Security-Policy: script-src 'strict-dynamic' 'nonce-dummy' 'sha256-yU6Q7nD1TCBB9JvY06iIJ8ONLOPU4g8ml5JCDgXkv+M=' 'sha256-EEoi70frWHkGFhK51NVIJkXpq72aPxSCNZEow37ZmRA='
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/scripthash-allowed.sub.html

    r246330 r279838  
    1414        });
    1515    </script>
    16    
     16
    1717    <script>
    1818        alert_assert('PASS (1/4)');
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/scripthash-basic-blocked.sub.html

    r246330 r279838  
    44<head>
    55    <!-- Programmatically converted from a WebKit Reftest, please forgive resulting idiosyncracies.-->
    6     <meta http-equiv="Content-Security-Policy" content="script-src 'self' 'nonce-abc' 'sha256-k7iO9DPkNQ7PcwPP+8XyYuRiCJ0p76Ofveol9g3mFNs=' 'sha256-EgE/bwVJ+ZLL9F5hNjDqD4C7nlFFrdDaKeNIJ2cUem4='; connect-src 'self';">
     6    <meta http-equiv="Content-Security-Policy" content="script-src 'self' 'nonce-abc' 'sha256-3iveTSiUbmzN7COYvdDwyaXXzJ3SrjKlTaOvQ/GdRpo=' 'sha256-EgE/bwVJ+ZLL9F5hNjDqD4C7nlFFrdDaKeNIJ2cUem4='; connect-src 'self';">
    77    <title>scripthash-basic-blocked</title>
    88    <script src="/resources/testharness.js"></script>
     
    1414        });
    1515    </script>
    16    
     16
    1717    <script>
    1818        var t_alert = async_test('Expecting alerts: ["PASS (1/1)"]');
     
    2727                for (var i = 0; i < expected_alerts.length; i++) {
    2828                    if (expected_alerts[i] == msg) {
    29                         assert_true(expected_alerts[i] == msg);
     29                        assert_equals(expected_alerts[i], msg);
    3030                        expected_alerts.splice(i, 1);
    3131                        if (expected_alerts.length == 0) {
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/scripthash-default-src.sub.html

    r253630 r279838  
    1212        });
    1313    </script>
    14    
     14
    1515    <script>done();</script>
    1616    </head>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/scripthash-ignore-unsafeinline.sub.html

    r246330 r279838  
    44<head>
    55    <!-- Programmatically converted from a WebKit Reftest, please forgive resulting idiosyncracies.-->
    6     <meta http-equiv="Content-Security-Policy" content="script-src 'self' 'unsafe-inline' 'sha256-k7iO9DPkNQ7PcwPP+8XyYuRiCJ0p76Ofveol9g3mFNs=' 'sha256-EgE/bwVJ+ZLL9F5hNjDqD4C7nlFFrdDaKeNIJ2cUem4=' 'sha256-lxHfHAe5I15v8qaArcZ5WiKmLU4CjV+3tJeQUqSIWBk='; connect-src 'self';">
    7    
     6    <meta http-equiv="Content-Security-Policy" content="script-src 'self' 'unsafe-inline' 'sha256-3iveTSiUbmzN7COYvdDwyaXXzJ3SrjKlTaOvQ/GdRpo=' 'sha256-EgE/bwVJ+ZLL9F5hNjDqD4C7nlFFrdDaKeNIJ2cUem4=' 'sha256-lxHfHAe5I15v8qaArcZ5WiKmLU4CjV+3tJeQUqSIWBk='; connect-src 'self';">
     7
    88    <title>scripthash-ignore-unsafeinline</title>
    99    <script src="/resources/testharness.js"></script>
     
    2323                for (var i = 0; i < expected_alerts.length; i++) {
    2424                    if (expected_alerts[i] == msg) {
    25                         assert_true(expected_alerts[i] == msg);
     25                        assert_equals(expected_alerts[i], msg);
    2626                        expected_alerts.splice(i, 1);
    2727                        if (expected_alerts.length == 0) {
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/scriptnonce-allowed.sub.html

    r246330 r279838  
    3232                for (var i = 0; i < expected_alerts.length; i++) {
    3333                    if (expected_alerts[i] == msg) {
    34                         assert_true(expected_alerts[i] == msg);
     34                        assert_equals(expected_alerts[i], msg);
    3535                        expected_alerts.splice(i, 1);
    3636                        if (expected_alerts.length == 0) {
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/scriptnonce-and-scripthash.sub.html

    r246330 r279838  
    3131                for (var i = 0; i < expected_alerts.length; i++) {
    3232                    if (expected_alerts[i] == msg) {
    33                         assert_true(expected_alerts[i] == msg);
     33                        assert_equals(expected_alerts[i], msg);
    3434                        expected_alerts.splice(i, 1);
    3535                        if (expected_alerts.length == 0) {
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/scriptnonce-ignore-unsafeinline.sub.html

    r246330 r279838  
    3131                for (var i = 0; i < expected_alerts.length; i++) {
    3232                    if (expected_alerts[i] == msg) {
    33                         assert_true(expected_alerts[i] == msg);
     33                        assert_equals(expected_alerts[i], msg);
    3434                        expected_alerts.splice(i, 1);
    3535                        if (expected_alerts.length == 0) {
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/scriptnonce-redirect.sub.html

    r246330 r279838  
    3131                for (var i = 0; i < expected_alerts.length; i++) {
    3232                    if (expected_alerts[i] == msg) {
    33                         assert_true(expected_alerts[i] == msg);
     33                        assert_equals(expected_alerts[i], msg);
    3434                        expected_alerts.splice(i, 1);
    3535                        if (expected_alerts.length == 0) {
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/support/w3c-import.log

    r254133 r279838  
    2525/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/support/worker-function-function.js
    2626/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/support/worker-function-function.js.sub.headers
    27 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/support/worker-importscripts.js
    28 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/support/worker-importscripts.js.sub.headers
    29 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/support/worker-set-timeout.js
    30 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/support/worker-set-timeout.js.sub.headers
     27/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/support/worker-with-script-src-none-importscripts.js
     28/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/support/worker-with-script-src-none-importscripts.js.sub.headers
     29/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/support/worker-with-script-src-none-set-timeout.js
     30/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/support/worker-with-script-src-none-set-timeout.js.sub.headers
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/w3c-import.log

    r263605 r279838  
    6161/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_double_policy_different_nonce.html
    6262/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_double_policy_different_nonce.html.headers
    63 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_double_policy_honor_source_expressions.html
    64 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_double_policy_honor_source_expressions.html.headers
     63/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_double_policy_honor_source_expressions.sub.html
     64/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_double_policy_honor_source_expressions.sub.html.headers
    6565/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_double_policy_report_only.html
    6666/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/script-src-strict_dynamic_double_policy_report_only.html.headers
     
    9191/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/scripthash-basic-blocked-error-event.html
    9292/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/scripthash-basic-blocked.sub.html
     93/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/scripthash-case-insensitive.sub.html
    9394/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/scripthash-changed-1.html
    9495/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/scripthash-changed-2.html
     
    105106/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/simpleSourcedScript.js
    106107/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/srcdoc-doesnt-bypass-script-src.sub.html
     108/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/worker-data-set-timeout.sub.html
    107109/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/worker-eval-blocked.sub.html
    108110/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/worker-function-function-blocked.sub.html
    109 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/worker-importscripts-blocked.sub.html
     111/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/worker-importscripts.sub.html
    110112/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/worker-script-src.sub.html
    111 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/worker-set-timeout-blocked.sub.html
     113/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/worker-set-timeout.sub.html
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/script-src/worker-eval-blocked.sub.html

    r246330 r279838  
    2222            log('Fail');
    2323        });
    24    
     24
    2525        try {
    2626            var worker = new Worker('/content-security-policy/script-src/support/worker-eval.js');
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/inside-service-worker.https.html

    r246330 r279838  
    1414      var sw = r.active || r.installing || r.waiting;
    1515      add_completion_callback(_ => r.unregister());
    16            
     16
    1717      // Forward 'securitypolicyviolation' events from the document into the
    1818      // worker (we shouldn't actually see any, so the worker will assert that
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/script-sample-no-opt-in.html

    r246330 r279838  
    3232          assert_equals(e.blockedURI, "inline");
    3333          assert_equals(e.sample, "");
    34         }));     
    35      
     34        }));
     35
    3636      document.body.append(a);
    3737      a.click();
     
    4646          assert_equals(e.blockedURI, "inline");
    4747          assert_equals(e.sample, "");
    48         }));     
    49      
     48        }));
     49
    5050      document.body.append(i);
    5151    }, "JavaScript URLs in iframes should not have a sample.");
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/script-sample.html

    r246330 r279838  
    3232          assert_equals(e.blockedURI, "inline");
    3333          assert_equals(e.sample, "assert_unreached('inline event handler')");
    34         }));     
    35      
     34        }));
     35
    3636      document.body.append(a);
    3737      a.click();
     
    4646          assert_equals(e.blockedURI, "inline");
    4747          assert_equals(e.sample, "javascript:'inline url'");
    48         }));     
    49      
     48        }));
     49
    5050      document.body.append(i);
    5151    }, "JavaScript URLs in iframes should have a sample.");
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/securitypolicyviolation-block-cross-origin-image-from-script.sub.html

    r254133 r279838  
    2121        assert_equals(e.statusCode, 200);
    2222      }));
    23    
     23
    2424    var s = document.createElement("script");
    2525    s.src = "{{location[scheme]}}://{{domains[www2]}}:{{location[port]}}/content-security-policy/support/inject-image.sub.js";
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/securitypolicyviolation-block-cross-origin-image.sub.html

    r254133 r279838  
    2121        assert_equals(e.statusCode, 200);
    2222      }));
    23    
     23
    2424    var i = document.createElement("img");
    2525    i.src = "{{location[scheme]}}://{{hosts[alt][]}}:{{location[port]}}/content-security-policy/support/fail.png";
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/securitypolicyviolation-block-image-from-script.sub.html

    r254133 r279838  
    2121        assert_equals(e.statusCode, 200);
    2222      }));
    23    
     23
    2424    var s = document.createElement("script");
    2525    s.src = "/content-security-policy/support/inject-image.sub.js";
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/securitypolicyviolation-block-image.sub.html

    r254133 r279838  
    2121        assert_equals(e.statusCode, 200);
    2222      }));
    23    
     23
    2424    var i = document.createElement("img");
    2525    i.src = "/content-security-policy/support/fail.png";
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/style-sample-no-opt-in.html

    r246330 r279838  
    1414      var s = document.createElement('style');
    1515      s.innerText = "p { omg: yay !important; }";
    16      
     16
    1717      waitForViolation(s)
    1818        .then(t.step_func_done(e => {
    1919          assert_equals(e.blockedURI, "inline");
    2020          assert_equals(e.sample, "");
    21         }));     
     21        }));
    2222
    2323      document.head.append(s);
     
    2828      p.setAttribute("style", "omg: yay !important;");
    2929      p.innerText = "Yay!";
    30      
     30
    3131      waitForViolation(p)
    3232        .then(t.step_func_done(e => {
    3333          assert_equals(e.blockedURI, "inline");
    3434          assert_equals(e.sample, "");
    35         }));     
     35        }));
    3636
    3737      document.head.append(p);
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/style-sample.html

    r246330 r279838  
    1414      var s = document.createElement('style');
    1515      s.innerText = "p { omg: yay !important; }";
    16      
     16
    1717      waitForViolation(s)
    1818        .then(t.step_func_done(e => {
    1919          assert_equals(e.blockedURI, "inline");
    2020          assert_equals(e.sample, "p { omg: yay !important; }");
    21         }));     
     21        }));
    2222
    2323      document.head.append(s);
     
    2828      p.setAttribute("style", "omg: yay !important;");
    2929      p.innerText = "Yay!";
    30      
     30
    3131      waitForViolation(p)
    3232        .then(t.step_func_done(e => {
    3333          assert_equals(e.blockedURI, "inline");
    3434          assert_equals(e.sample, "omg: yay !important;");
    35         }));     
     35        }));
    3636
    3737      document.head.append(p);
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/w3c-import.log

    r246330 r279838  
    2121/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/img-src-redirect-upgrade-reporting.https.html
    2222/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/img-src-redirect-upgrade-reporting.https.html.headers
     23/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/img-src-redirect.sub.html
    2324/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/inside-dedicated-worker.html
    2425/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/inside-service-worker.https.html
     
    3031/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/securitypolicyviolation-block-image-from-script.sub.html
    3132/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/securitypolicyviolation-block-image.sub.html
     33/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/source-file-blob-scheme.html
     34/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/source-file-data-scheme.html
    3235/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/style-sample-no-opt-in.html
    3336/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/style-sample.html
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/injected-inline-style-allowed.sub.html

    r246330 r279838  
    2222        FAIL 1/2
    2323    </div>
    24    
     24
    2525    <div id="test2">
    2626        FAIL 2/2
    2727    </div>
    28    
     28
    2929    <script src="support/inject-style.js"></script>
    3030    <script>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/inline-style-allowed-while-cloning-objects.sub.html

    r254133 r279838  
    1313        var t = async_test("Test that violation report event was fired");
    1414        window.addEventListener("securitypolicyviolation", t.step_func_done(function(e) {
    15             assert_equals(e.violatedDirective, "style-src");
     15            assert_equals(e.violatedDirective, "style-src-attr");
    1616        }));
    1717        window.onload = function() {
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/inline-style-allowed.sub.html

    r246330 r279838  
    1515       });
    1616    </script>
    17    
     17
    1818    <style>
    1919        .target {
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-allowed.sub.html

    r246330 r279838  
    1414            log("Fail");
    1515        });
    16     </script>   
     16    </script>
    1717    <link rel="stylesheet" href="resources/blue.css">
    1818</head>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-blocked.sub-expected.txt

    r246330 r279838  
    11
    2 FAIL Expecting logs: ["violated-directive=style-src","PASS"] assert_unreached: Logging timeout, expected logs violated-directive=style-src not sent. Reached unreachable code
     2FAIL Expecting logs: ["violated-directive=style-src-elem","PASS"] assert_unreached: Logging timeout, expected logs violated-directive=style-src-elem not sent. Reached unreachable code
    33
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-blocked.sub.html

    r246330 r279838  
    88    <script src="/resources/testharness.js"></script>
    99    <script src="/resources/testharnessreport.js"></script>
    10     <script src='../support/logTest.sub.js?logs=["violated-directive=style-src","PASS"]'></script>
     10    <script src='../support/logTest.sub.js?logs=["violated-directive=style-src-elem","PASS"]'></script>
    1111    <script src="../support/alertAssert.sub.js?alerts=[]"></script>
    1212    <script>
     
    1414            log("violated-directive=" + e.violatedDirective);
    1515        });
    16     </script>   
     16    </script>
    1717    <link rel="stylesheet" href="resources/blue.css">
    1818</head>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-hash-allowed.html

    r246330 r279838  
    2929        var contentEl = document.getElementById(contentId);
    3030        var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left');
    31         assert_true(marginLeftVal == "2px")
     31        assert_equals(marginLeftVal, "2px")
    3232      }
    3333      t.step(function() {
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-hash-blocked.html

    r246330 r279838  
    3030        var contentEl = document.getElementById(contentId);
    3131        var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left');
    32         if (assertTrue) assert_true(marginLeftVal == "2px");
    33         else assert_false(marginLeftVal == "2px");
     32        if (assertTrue) assert_equals(marginLeftVal, "2px");
     33        else assert_not_equals(marginLeftVal, "2px");
    3434      }
    3535
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-hash-default-src-allowed.html

    r246330 r279838  
    2929        var contentEl = document.getElementById(contentId);
    3030        var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left');
    31         assert_true(marginLeftVal == "2px")
     31        assert_equals(marginLeftVal, "2px")
    3232      }
    3333      t.step(function() {
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-imported-style-allowed.sub.html

    r246330 r279838  
    2222        var contentEl = document.getElementById("content");
    2323        var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left');
    24         assert_false(marginLeftVal == "2px")
     24        assert_not_equals(marginLeftVal, "2px")
    2525        t.done();
    2626      });
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-imported-style-blocked.html

    r246330 r279838  
    3030        var contentEl = document.getElementById("content");
    3131        var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left');
    32         assert_false(marginLeftVal == "2px");
     32        assert_not_equals(marginLeftVal, "2px");
    3333        t.done();
    3434      });
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-injected-inline-style-allowed.html

    r246330 r279838  
    2424          var contentEl = document.getElementById("content");
    2525          var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left');
    26           assert_true(marginLeftVal == "2px");
     26          assert_equals(marginLeftVal, "2px");
    2727          var marginRightVal = getComputedStyle(contentEl).getPropertyValue('margin-right');
    28           assert_true(marginRightVal == "2px");
     28          assert_equals(marginRightVal, "2px");
    2929        });
    3030      });
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-injected-inline-style-blocked.html

    r246330 r279838  
    3131
    3232        var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left');
    33         assert_false(marginLeftVal == "2px");
     33        assert_not_equals(marginLeftVal, "2px");
    3434        var marginRightVal = getComputedStyle(contentEl).getPropertyValue('margin-right');
    35         assert_false(marginRightVal == "2px");
     35        assert_not_equals(marginRightVal, "2px");
    3636      });
    3737    </script>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-injected-stylesheet-allowed.sub-expected.txt

    r246330 r279838  
    11Blocked access to external URL http://www1.localhost:8800/content-security-policy/style-src/resources/style-src.css
    22
    3 FAIL Programatically injected stylesheet should load assert_true: expected true got false
     3FAIL Programatically injected stylesheet should load assert_equals: expected "2px" but got "0px"
    44Lorem ipsum
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-injected-stylesheet-allowed.sub.html

    r246330 r279838  
    2121        var contentEl = document.getElementById("content");
    2222        var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left');
    23         assert_true(marginLeftVal == "2px");
     23        assert_equals(marginLeftVal, "2px");
    2424      });
    2525
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-injected-stylesheet-blocked.sub.html

    r246330 r279838  
    2525        var contentEl = document.getElementById("content");
    2626        var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left');
    27         assert_false(marginLeftVal == "2px");
     27        assert_not_equals(marginLeftVal, "2px");
    2828      });
    2929
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-inline-style-allowed.html

    r246330 r279838  
    2626        var contentEl = document.getElementById("content");
    2727        var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left');
    28         assert_true(marginLeftVal == "2px");
     28        assert_equals(marginLeftVal, "2px");
    2929        t.done();
    3030      }, "Inline style should not be applied");
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-inline-style-attribute-allowed.html

    r246330 r279838  
    1212        var contentEl = document.getElementById("content");
    1313        var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left');
    14         assert_true(marginLeftVal == "2px");
     14        assert_equals(marginLeftVal, "2px");
    1515      });
    1616    </script>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-inline-style-attribute-blocked.html

    r246330 r279838  
    1616        var contentEl = document.getElementById("content");
    1717        var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left');
    18         assert_false(marginLeftVal == "2px");
     18        assert_not_equals(marginLeftVal, "2px");
    1919      });
    2020    </script>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-inline-style-blocked.html

    r246330 r279838  
    3030        var contentEl = document.getElementById("content");
    3131        var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left');
    32         assert_false(marginLeftVal == "2px");
     32        assert_not_equals(marginLeftVal, "2px");
    3333        t.done();
    3434      });
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-inline-style-nonce-allowed.html

    r246330 r279838  
    2626        var contentEl = document.getElementById("content");
    2727        var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left');
    28         assert_true(marginLeftVal == "2px");
     28        assert_equals(marginLeftVal, "2px");
    2929        t.done();
    3030      });
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-inline-style-nonce-blocked-error-event.html

    r246330 r279838  
    2828        function verifyStep1() {
    2929            var marginLeft = getComputedStyle(document.querySelector("#content")).getPropertyValue('margin-left');
    30             assert_false(marginLeft == '2px', "Content still does not have a 2px margin-left after initial style.");
     30            assert_not_equals(marginLeft, '2px', "Content still does not have a 2px margin-left after initial style.");
    3131        }
    3232
     
    4040        function verifyStep2() {
    4141            var marginLeft = getComputedStyle(document.querySelector("#content")).getPropertyValue('margin-left');
    42             assert_false(marginLeft == '2px', "Content still does not have a 2px margin-left after inserted style.");
     42            assert_not_equals(marginLeft, '2px', "Content still does not have a 2px margin-left after inserted style.");
    4343        }
    4444
     
    4949        function verifyStep3() {
    5050            var marginLeft = getComputedStyle(document.querySelector("#content")).getPropertyValue('margin-left');
    51             assert_false(marginLeft == '2px', "Content still does not have a 2px margin-left after changing style.");
     51            assert_not_equals(marginLeft, '2px', "Content still does not have a 2px margin-left after changing style.");
    5252            test.done();
    5353        }
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-inline-style-nonce-blocked.html

    r246330 r279838  
    2929        var contentEl = document.getElementById("content");
    3030        var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left');
    31         assert_false(marginLeftVal == "2px");
     31        assert_not_equals(marginLeftVal, "2px");
    3232        t.done();
    3333      });
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-multiple-policies-multiple-hashing-algorithms.html.sub.headers

    r246330 r279838  
    44Pragma: no-cache
    55Set-Cookie: style-src-multiple-policies-multiple-hashing-algorithms={{$id:uuid()}}; Path=/content-security-policy/style-src/
    6 Content-Security-Policy: style-src 'sha256-rB6kiow2O3eFUeTNyyLeK3wV0+l7vNB90J1aqllKvjg='; script-src 'unsafe-inline' 'self'; report-uri ../support/report.py?op=put&reportID={{$id}}
    7 Content-Security-Policy: style-src 'sha384-DAShdG5sejEaOdWfT+TQMRP5mHssKiUNjFggNnElIvIoj048XQlacVRs+za2AM1a'; script-src 'unsafe-inline' 'self'; report-uri ../support/report.py?op=put&reportID={{$id}}
     6Content-Security-Policy: style-src 'sha256-rB6kiow2O3eFUeTNyyLeK3wV0+l7vNB90J1aqllKvjg='; script-src 'unsafe-inline' 'self'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
     7Content-Security-Policy: style-src 'sha384-DAShdG5sejEaOdWfT+TQMRP5mHssKiUNjFggNnElIvIoj048XQlacVRs+za2AM1a'; script-src 'unsafe-inline' 'self'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-none-blocked.html

    r246330 r279838  
    2525        var contentEl = document.getElementById("content");
    2626        var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left');
    27         assert_false(marginLeftVal == "2px");
     27        assert_not_equals(marginLeftVal, "2px");
    2828        t.done();
    2929      });
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-star-allowed.html

    r246330 r279838  
    2222        var contentEl = document.getElementById("content");
    2323        var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left');
    24         assert_true(marginLeftVal == "2px");
     24        assert_equals(marginLeftVal, "2px");
    2525        t.done();
    2626      });
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-stylesheet-nonce-allowed.html

    r254133 r279838  
    2222        var contentEl = document.getElementById("content");
    2323        var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left');
    24         assert_true(marginLeftVal == "2px");
     24        assert_equals(marginLeftVal, "2px");
    2525        t.done();
    2626      });
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-stylesheet-nonce-blocked.html

    r254133 r279838  
    2525        var contentEl = document.getElementById("content");
    2626        var marginLeftVal = getComputedStyle(contentEl).getPropertyValue('margin-left');
    27         assert_false(marginLeftVal == "2px");
     27        assert_not_equals(marginLeftVal, "2px");
    2828        t.done();
    2929      });
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/stylehash-allowed.sub.html

    r246330 r279838  
    1313            alert_assert("Fail");
    1414        });
    15    
     15
    1616        var t_alert = async_test('Expecting alerts: ["PASS (1/4): The \'#p1\' element\'s text is green, which means the style was correctly applied.","PASS (2/4): The \'#p2\' element\'s text is green, which means the style was correctly applied.","PASS (3/4): The \'#p3\' element\'s text is green, which means the style was correctly applied.","PASS (4/4): The \'#p4\' element\'s text is green, which means the style was correctly applied."]');
    1717        var expected_alerts = ["PASS (1/4): The '#p1' element's text is green, which means the style was correctly applied.", "PASS (2/4): The '#p2' element's text is green, which means the style was correctly applied.", "PASS (3/4): The '#p3' element's text is green, which means the style was correctly applied.", "PASS (4/4): The '#p4' element's text is green, which means the style was correctly applied."];
     
    2525                for (var i = 0; i < expected_alerts.length; i++) {
    2626                    if (expected_alerts[i] == msg) {
    27                         assert_true(expected_alerts[i] == msg);
     27                        assert_equals(expected_alerts[i], msg);
    2828                        expected_alerts.splice(i, 1);
    2929                        if (expected_alerts.length == 0) {
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/stylehash-basic-blocked.sub.html

    r246330 r279838  
    2525                for (var i = 0; i < expected_alerts.length; i++) {
    2626                    if (expected_alerts[i] == msg) {
    27                         assert_true(expected_alerts[i] == msg);
     27                        assert_equals(expected_alerts[i], msg);
    2828                        expected_alerts.splice(i, 1);
    2929                        if (expected_alerts.length == 0) {
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/w3c-import.log

    r246330 r279838  
    2828/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-hash-allowed.html
    2929/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-hash-blocked.html
     30/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-hash-case-insensitive.html
    3031/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-hash-default-src-allowed.html
    3132/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-imported-style-allowed.sub.html
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/support/alertAssert.sub.js

    r246330 r279838  
    2929         for (var i = 0; i < expected_alerts.length; i++) {
    3030             if (expected_alerts[i] == msg) {
    31                  assert_true(expected_alerts[i] == msg);
     31                 assert_equals(expected_alerts[i], msg);
    3232                 expected_alerts.splice(i, 1);
    3333                 if (expected_alerts.length == 0) {
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/support/checkReport.sub.js

    r279169 r279838  
    4949  // not exceed the test timeouts set by vendors otherwise the test would fail.
    5050  var timeout = document.querySelector("meta[name=timeout][content=long]") ? 20 : 3;
    51   var reportLocation = location.protocol + "//" + location.host + "/content-security-policy/support/report.py?op=retrieve_report&timeout=" + timeout + "&reportID=" + reportID;
     51  var reportLocation = location.protocol + "//" + location.host + "/reporting/resources/report.py?op=retrieve_report&timeout=" + timeout + "&reportID=" + reportID;
    5252
    5353  if (testName == "") testName = "Violation report status OK.";
     
    116116        cookieTest.done();
    117117      });
    118       var cReportLocation = location.protocol + "//" + location.host + "/content-security-policy/support/report.py?op=retrieve_cookies&timeout=" + timeout + "&reportID=" + reportID;
     118      var cReportLocation = location.protocol + "//" + location.host + "/reporting/resources/report.py?op=retrieve_cookies&timeout=" + timeout + "&reportID=" + reportID;
    119119      cookieReport.open("GET", cReportLocation, true);
    120120      cookieReport.send();
     
    131131        reportCountTest.done();
    132132      });
    133       var cReportLocation = location.protocol + "//" + location.host + "/content-security-policy/support/report.py?op=retrieve_count&timeout=" + timeout + "&reportID=" + reportID;
     133      var cReportLocation = location.protocol + "//" + location.host + "/reporting/resources/report.py?op=retrieve_count&timeout=" + timeout + "&reportID=" + reportID;
    134134      reportCountReport.open("GET", cReportLocation, true);
    135135      reportCountReport.send();
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/support/echo-policy.py

    r246330 r279838  
    11def main(request, response):
    2     policy = request.GET.first("policy");
    3     return [("Content-Type", "text/html"), ("Content-Security-Policy", policy)], "<!DOCTYPE html><title>Echo.</title>"
     2    policy = request.GET.first(b"policy")
     3    return [(b"Content-Type", b"text/html"), (b"Content-Security-Policy", policy)], b"<!DOCTYPE html><title>Echo.</title>"
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/support/logTest.sub.js

    r246330 r279838  
    2727            for (var i = 0; i < expected_logs.length; i++) {
    2828                if (expected_logs[i] == msg) {
    29                     assert_true(expected_logs[i] == msg);
     29                    assert_equals(expected_logs[i], msg);
    3030                    expected_logs.splice(i, 1);
    3131                    if (expected_logs.length == 0) {
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/support/prefetch-helper.js

    r246330 r279838  
    1 test(t => {
    2   assert_true(document.createElement('link').relList.supports('prefetch'));
    3 }, "Browser supports prefetch.");
    4 
    5 test(t => {
    6   assert_true(!!window.PerformanceResourceTiming);
    7 }, "Browser supports performance APIs.");
     1setup(_ => {
     2  assert_implements_optional(
     3    document.createElement('link').relList.supports('prefetch'),
     4    "Browser supports prefetch.");
     5  assert_implements_optional(
     6    "PerformanceResourceTiming" in window,
     7    "Browser supports performance APIs.");
     8});
    89
    910async function waitUntilResourceDownloaded(url) {
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/support/resource.py

    r246330 r279838  
    11def main(request, response):
    22    headers = []
    3     headers.append(("Access-Control-Allow-Origin", "*"))
     3    headers.append((b"Access-Control-Allow-Origin", b"*"))
    44
    5     return headers, "{ \"result\": \"success\" }"
     5    return headers, b"{ \"result\": \"success\" }"
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/support/testharness-helper.js

    r263605 r279838  
    4141// function builds a test that asserts that the ping is received,
    4242// and that no CSP event fires.
    43 function assert_worker_is_loaded(url, description) {
     43function assert_worker_is_loaded(url, description, expected_message = "ping") {
    4444  async_test(t => {
    4545    assert_no_csp_event_for_url(t, url);
     
    4848    waitUntilEvent(w, "message")
    4949      .then(t.step_func_done(e => {
    50         assert_equals(e.data, "ping");
     50        assert_equals(e.data, expected_message);
    5151      }));
    5252  }, description);
    5353}
    5454
    55 function assert_shared_worker_is_loaded(url, description) {
     55function assert_shared_worker_is_loaded(url, description, expected_message = "ping") {
    5656  async_test(t => {
    5757    assert_no_csp_event_for_url(t, url);
     
    6060    waitUntilEvent(w.port, "message")
    6161      .then(t.step_func_done(e => {
    62         assert_equals(e.data, "ping");
     62        assert_equals(e.data, expected_message);
    6363      }));
    6464    w.port.start();
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/support/w3c-import.log

    r246330 r279838  
    4343/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/support/prefetch-subresource.css
    4444/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/support/prefetch-subresource.css.headers
    45 /LayoutTests/imported/w3c/web-platform-tests/content-security-policy/support/report.py
    4645/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/support/resource.py
    4746/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/support/service-worker-helper.js
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/eval-blocked-in-about-blank-iframe.sub.html

    r246330 r279838  
    2020    });
    2121    window.onmessage = function(e) {
    22         log(e.data);   
     22        log(e.data);
    2323    }
    2424    window.onload = function() {
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/eval-scripts-setInterval-allowed.sub.html

    r246330 r279838  
    1616    log("Fail");
    1717  });
    18  
     18
    1919  var id_string = setInterval("clearInterval(id_string); log('PASS 1 of 2')", 0);
    2020  if (id_string == 0)
    2121    log('FAIL: Return value for string (should not be 0): ' + id_string);
    22  
     22
    2323  var id_function = setInterval(function() {
    2424    clearInterval(id_function);
    2525    log('PASS 2 of 2');
    2626  }, 0);
    27  
     27
    2828  if (id_function == 0)
    2929    log('FAIL');
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/eval-scripts-setInterval-blocked.sub.html

    r246330 r279838  
    1515    log("violated-directive=" + e.violatedDirective);
    1616  });
    17  
     17
    1818  var id = setInterval("alert_assert('FAIL')", 0);
    1919  if (id != 0)
    2020    log('FAIL: Return value for string (should be 0): ' + id);
    21  
     21
    2222  var id = setInterval(function() {
    2323    clearInterval(id);
    2424    log('PASS');
    2525  }, 0);
    26  
     26
    2727  if (id == 0)
    2828    log('FAIL');
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/eval-scripts-setTimeout-allowed.sub.html

    r246330 r279838  
    1515    log("Fail");
    1616  });
    17  
     17
    1818  var id = setTimeout("log('PASS 1 of 2')", 0);
    1919  if (id == 0)
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/eval-scripts-setTimeout-blocked.sub.html

    r246330 r279838  
    1515    log("violated-directive=" + e.violatedDirective);
    1616  });
    17  
     17
    1818  var id = setTimeout("alert_assert('FAIL')", 0);
    1919  if (id != 0)
    2020    log('FAIL');
    21    
     21
    2222  var id = setTimeout(function() {
    2323    log('PASS');
    2424  }, 0);
    25  
     25
    2626  if (id == 0)
    2727    log('FAIL');
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/function-constructor-blocked.sub.html

    r246330 r279838  
    1717            log("violated-directive=" + e.violatedDirective);
    1818        });
    19        
     19
    2020        try {
    2121            (new Function("log('FAIL')"))();
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/w3c-import.log

    r246330 r279838  
    1919/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/eval-blocked-in-about-blank-iframe.sub.html
    2020/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/eval-blocked.sub.html
     21/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/eval-in-iframe.html
    2122/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/eval-scripts-setInterval-allowed.sub.html
    2223/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-eval/eval-scripts-setInterval-blocked.sub.html
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-hashes/javascript_src_allowed-href_blank.html

    r246330 r279838  
    1414<body>
    1515    <div id='log'></div>
    16     <a target="_blank" href='javascript:opener.t1.done();' id='test'>
     16    <a target="_blank" rel="opener" href='javascript:opener.t1.done();' id='test'>
    1717    <script nonce='abc'>
    1818        var t1 = async_test("Test that the javascript: src is allowed to run");
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-hashes/javascript_src_allowed-window_location.html

    r246330 r279838  
    1919        });
    2020
    21         window.open('support/child_window_location_navigate.sub.html' + 
     21        window.open('support/child_window_location_navigate.sub.html' +
    2222              '?csp=' + encodeURI("script-src 'unsafe-hashes' 'nonce-abc' 'sha256-IIiAJ8UuliU8o1qAv6CV4P3R8DeTf/v3MrsCwXW171Y='") +
    2323              '&url=' + encodeURI("javascript:opener.postMessage('pass', '*')"));
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-hashes/javascript_src_denied_missing_unsafe_hashes-window_location.html

    r246330 r279838  
    1919        });
    2020
    21         window.open('support/child_window_location_navigate.sub.html' + 
     21        window.open('support/child_window_location_navigate.sub.html' +
    2222              '?csp=' + encodeURI("script-src 'nonce-abc' 'sha256-IIiAJ8UuliU8o1qAv6CV4P3R8DeTf/v3MrsCwXW171Y='") +
    2323              '&url=' + encodeURI("javascript:opener.postMessage('pass', '*')"));
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-hashes/javascript_src_denied_wrong_hash-window_location.html

    r246330 r279838  
    1919        });
    2020
    21         window.open('support/child_window_location_navigate.sub.html' + 
     21        window.open('support/child_window_location_navigate.sub.html' +
    2222              '?csp=' + encodeURI("script-src 'unsafe-hashes' 'nonce-abc' 'sha256-VjH6k67F4kobUnNDOBE85QiJ9cuZMiYT6desKXvezVg='") +
    2323              '&url=' + encodeURI("javascript:opener.postMessage('pass', '*')"));
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-hashes/script_event_handlers_allowed.html

    r246330 r279838  
    1313    <script nonce='abc'>
    1414        var t1 = async_test("Test that the inline event handler is allowed to run");
    15        
     15
    1616        window.addEventListener('securitypolicyviolation', t1.unreached_func("Should have not raised any event"));
    1717    </script>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/unsafe-hashes/support/child_window_location_navigate.sub.html

    r246330 r279838  
    77
    88<body>
     9
     10  <span id="escape">{{GET[url]}}</span>
     11
    912  <script nonce='abc'>
    1013    window.addEventListener('securitypolicyviolation', function(e) {
     
    1215    });
    1316
    14     window.location.href = "{{GET[url]}}";
     17    window.location.href = document.getElementById("escape").textContent;
    1518  </script>
    1619</body>
  • trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/w3c-import.log

    r246330 r279838  
    1818/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/README.css
    1919/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/README.html
     20/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/spec.src.json
  • trunk/LayoutTests/platform/mac-wk1/TestExpectations

    r279725 r279838  
    345345http/wpt/cache-storage [ Skip ]
    346346http/wpt/service-workers [ Skip ]
     347imported/w3c/web-platform-tests/content-security-policy/inside-worker/serviceworker-report-only.https.sub.html [ Skip ]
     348imported/w3c/web-platform-tests/content-security-policy/sandbox/service-worker-sandbox.https.html [ Skip ]
    347349imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/inside-service-worker.https.html [ Skip ]
    348350imported/w3c/web-platform-tests/content-security-policy/worker-src/service-child.https.sub.html [ Skip ]
  • trunk/LayoutTests/platform/mac-wk1/imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-same-none-block-expected.txt

    r262312 r279838  
    1 Blocked access to external URL http://www1.localhost:8801/content-security-policy/frame-ancestors/support/frame-ancestors.sub.html?policy=&#x27;none&%23x27;
     1Blocked access to external URL http://www1.localhost:8801/content-security-policy/frame-ancestors/support/frame-ancestors.sub.html?policy=%27none%27
    22
    33
  • trunk/LayoutTests/platform/mac-wk1/imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-same-self-block-expected.txt

    r262312 r279838  
    1 Blocked access to external URL http://www1.localhost:8801/content-security-policy/frame-ancestors/support/frame-ancestors.sub.html?policy=&#x27;self&%23x27;
     1Blocked access to external URL http://www1.localhost:8801/content-security-policy/frame-ancestors/support/frame-ancestors.sub.html?policy=%27self%27
    22
    33
  • trunk/LayoutTests/tests-options.json

    r279585 r279838  
    567567        "slow"
    568568    ],
     569    "imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/required_csp-header-crlf.html": [
     570        "slow"
     571    ],
    569572    "imported/w3c/web-platform-tests/content-security-policy/embedded-enforcement/required_csp-header.html": [
    570573        "slow"
    571574    ],
     575    "imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-same-star-allow.html": [
     576        "slow"
     577    ],
    572578    "imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/report-blocked-frame.sub.html": [
    573579        "slow"
    574580    ],
    575581    "imported/w3c/web-platform-tests/content-security-policy/frame-ancestors/report-only-frame.sub.html": [
     582        "slow"
     583    ],
     584    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/script-tag.http.html": [
     585        "slow"
     586    ],
     587    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/script-tag.https.html": [
     588        "slow"
     589    ],
     590    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-classic.http.html": [
     591        "slow"
     592    ],
     593    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-classic.https.html": [
     594        "slow"
     595    ],
     596    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-import-data.http.html": [
     597        "slow"
     598    ],
     599    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-import-data.https.html": [
     600        "slow"
     601    ],
     602    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-import.http.html": [
     603        "slow"
     604    ],
     605    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-import.https.html": [
     606        "slow"
     607    ],
     608    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-module.http.html": [
     609        "slow"
     610    ],
     611    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/sharedworker-module.https.html": [
     612        "slow"
     613    ],
     614    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-classic.http.html": [
     615        "slow"
     616    ],
     617    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-classic.https.html": [
     618        "slow"
     619    ],
     620    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-import-data.http.html": [
     621        "slow"
     622    ],
     623    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-import-data.https.html": [
     624        "slow"
     625    ],
     626    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-import.http.html": [
     627        "slow"
     628    ],
     629    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-import.https.html": [
     630        "slow"
     631    ],
     632    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-module.http.html": [
     633        "slow"
     634    ],
     635    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worker-module.https.html": [
     636        "slow"
     637    ],
     638    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-animation-import-data.https.html": [
     639        "slow"
     640    ],
     641    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-animation.https.html": [
     642        "slow"
     643    ],
     644    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-audio-import-data.https.html": [
     645        "slow"
     646    ],
     647    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-audio.https.html": [
     648        "slow"
     649    ],
     650    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-layout-import-data.https.html": [
     651        "slow"
     652    ],
     653    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-layout.https.html": [
     654        "slow"
     655    ],
     656    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-paint-import-data.https.html": [
     657        "slow"
     658    ],
     659    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-self/worklet-paint.https.html": [
     660        "slow"
     661    ],
     662    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/script-tag.http.html": [
     663        "slow"
     664    ],
     665    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/script-tag.https.html": [
     666        "slow"
     667    ],
     668    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-classic.http.html": [
     669        "slow"
     670    ],
     671    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-classic.https.html": [
     672        "slow"
     673    ],
     674    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-import-data.http.html": [
     675        "slow"
     676    ],
     677    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-import-data.https.html": [
     678        "slow"
     679    ],
     680    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-import.http.html": [
     681        "slow"
     682    ],
     683    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-import.https.html": [
     684        "slow"
     685    ],
     686    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-module.http.html": [
     687        "slow"
     688    ],
     689    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/sharedworker-module.https.html": [
     690        "slow"
     691    ],
     692    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-classic.http.html": [
     693        "slow"
     694    ],
     695    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-classic.https.html": [
     696        "slow"
     697    ],
     698    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-import-data.http.html": [
     699        "slow"
     700    ],
     701    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-import-data.https.html": [
     702        "slow"
     703    ],
     704    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-import.http.html": [
     705        "slow"
     706    ],
     707    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-import.https.html": [
     708        "slow"
     709    ],
     710    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-module.http.html": [
     711        "slow"
     712    ],
     713    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worker-module.https.html": [
     714        "slow"
     715    ],
     716    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-animation-import-data.https.html": [
     717        "slow"
     718    ],
     719    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-animation.https.html": [
     720        "slow"
     721    ],
     722    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-audio-import-data.https.html": [
     723        "slow"
     724    ],
     725    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-audio.https.html": [
     726        "slow"
     727    ],
     728    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-layout-import-data.https.html": [
     729        "slow"
     730    ],
     731    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-layout.https.html": [
     732        "slow"
     733    ],
     734    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-paint-import-data.https.html": [
     735        "slow"
     736    ],
     737    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/script-src-wildcard/worklet-paint.https.html": [
     738        "slow"
     739    ],
     740    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/script-tag.http.html": [
     741        "slow"
     742    ],
     743    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/script-tag.https.html": [
     744        "slow"
     745    ],
     746    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-classic.http.html": [
     747        "slow"
     748    ],
     749    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-classic.https.html": [
     750        "slow"
     751    ],
     752    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-import-data.http.html": [
     753        "slow"
     754    ],
     755    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-import-data.https.html": [
     756        "slow"
     757    ],
     758    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-import.http.html": [
     759        "slow"
     760    ],
     761    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-import.https.html": [
     762        "slow"
     763    ],
     764    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-module.http.html": [
     765        "slow"
     766    ],
     767    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/sharedworker-module.https.html": [
     768        "slow"
     769    ],
     770    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-classic.http.html": [
     771        "slow"
     772    ],
     773    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-classic.https.html": [
     774        "slow"
     775    ],
     776    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-import-data.http.html": [
     777        "slow"
     778    ],
     779    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-import-data.https.html": [
     780        "slow"
     781    ],
     782    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-import.http.html": [
     783        "slow"
     784    ],
     785    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-import.https.html": [
     786        "slow"
     787    ],
     788    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-module.http.html": [
     789        "slow"
     790    ],
     791    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worker-module.https.html": [
     792        "slow"
     793    ],
     794    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-animation-import-data.https.html": [
     795        "slow"
     796    ],
     797    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-animation.https.html": [
     798        "slow"
     799    ],
     800    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-audio-import-data.https.html": [
     801        "slow"
     802    ],
     803    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-audio.https.html": [
     804        "slow"
     805    ],
     806    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-layout-import-data.https.html": [
     807        "slow"
     808    ],
     809    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-layout.https.html": [
     810        "slow"
     811    ],
     812    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-paint-import-data.https.html": [
     813        "slow"
     814    ],
     815    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-none/worklet-paint.https.html": [
     816        "slow"
     817    ],
     818    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/script-tag.http.html": [
     819        "slow"
     820    ],
     821    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/script-tag.https.html": [
     822        "slow"
     823    ],
     824    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-classic.http.html": [
     825        "slow"
     826    ],
     827    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-classic.https.html": [
     828        "slow"
     829    ],
     830    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-import-data.http.html": [
     831        "slow"
     832    ],
     833    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-import-data.https.html": [
     834        "slow"
     835    ],
     836    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-import.http.html": [
     837        "slow"
     838    ],
     839    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-import.https.html": [
     840        "slow"
     841    ],
     842    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-module.http.html": [
     843        "slow"
     844    ],
     845    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/sharedworker-module.https.html": [
     846        "slow"
     847    ],
     848    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-classic.http.html": [
     849        "slow"
     850    ],
     851    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-classic.https.html": [
     852        "slow"
     853    ],
     854    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-import-data.http.html": [
     855        "slow"
     856    ],
     857    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-import-data.https.html": [
     858        "slow"
     859    ],
     860    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-import.http.html": [
     861        "slow"
     862    ],
     863    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-import.https.html": [
     864        "slow"
     865    ],
     866    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-module.http.html": [
     867        "slow"
     868    ],
     869    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worker-module.https.html": [
     870        "slow"
     871    ],
     872    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-animation-import-data.https.html": [
     873        "slow"
     874    ],
     875    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-animation.https.html": [
     876        "slow"
     877    ],
     878    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-audio-import-data.https.html": [
     879        "slow"
     880    ],
     881    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-audio.https.html": [
     882        "slow"
     883    ],
     884    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-layout-import-data.https.html": [
     885        "slow"
     886    ],
     887    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-layout.https.html": [
     888        "slow"
     889    ],
     890    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-paint-import-data.https.html": [
     891        "slow"
     892    ],
     893    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-self/worklet-paint.https.html": [
     894        "slow"
     895    ],
     896    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/script-tag.http.html": [
     897        "slow"
     898    ],
     899    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/script-tag.https.html": [
     900        "slow"
     901    ],
     902    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-classic.http.html": [
     903        "slow"
     904    ],
     905    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-classic.https.html": [
     906        "slow"
     907    ],
     908    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-import-data.http.html": [
     909        "slow"
     910    ],
     911    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-import-data.https.html": [
     912        "slow"
     913    ],
     914    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-import.http.html": [
     915        "slow"
     916    ],
     917    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-import.https.html": [
     918        "slow"
     919    ],
     920    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-module.http.html": [
     921        "slow"
     922    ],
     923    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/sharedworker-module.https.html": [
     924        "slow"
     925    ],
     926    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-classic.http.html": [
     927        "slow"
     928    ],
     929    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-classic.https.html": [
     930        "slow"
     931    ],
     932    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-import-data.http.html": [
     933        "slow"
     934    ],
     935    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-import-data.https.html": [
     936        "slow"
     937    ],
     938    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-import.http.html": [
     939        "slow"
     940    ],
     941    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-import.https.html": [
     942        "slow"
     943    ],
     944    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-module.http.html": [
     945        "slow"
     946    ],
     947    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worker-module.https.html": [
     948        "slow"
     949    ],
     950    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-animation-import-data.https.html": [
     951        "slow"
     952    ],
     953    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-animation.https.html": [
     954        "slow"
     955    ],
     956    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-audio-import-data.https.html": [
     957        "slow"
     958    ],
     959    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-audio.https.html": [
     960        "slow"
     961    ],
     962    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-layout-import-data.https.html": [
     963        "slow"
     964    ],
     965    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-layout.https.html": [
     966        "slow"
     967    ],
     968    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-paint-import-data.https.html": [
     969        "slow"
     970    ],
     971    "imported/w3c/web-platform-tests/content-security-policy/gen/top.http-rp/worker-src-wildcard/worklet-paint.https.html": [
     972        "slow"
     973    ],
     974    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/script-tag.http.html": [
     975        "slow"
     976    ],
     977    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/script-tag.https.html": [
     978        "slow"
     979    ],
     980    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-classic.http.html": [
     981        "slow"
     982    ],
     983    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-classic.https.html": [
     984        "slow"
     985    ],
     986    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-import-data.http.html": [
     987        "slow"
     988    ],
     989    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-import-data.https.html": [
     990        "slow"
     991    ],
     992    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-import.http.html": [
     993        "slow"
     994    ],
     995    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-import.https.html": [
     996        "slow"
     997    ],
     998    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-module.http.html": [
     999        "slow"
     1000    ],
     1001    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/sharedworker-module.https.html": [
     1002        "slow"
     1003    ],
     1004    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-classic.http.html": [
     1005        "slow"
     1006    ],
     1007    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-classic.https.html": [
     1008        "slow"
     1009    ],
     1010    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-import-data.http.html": [
     1011        "slow"
     1012    ],
     1013    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-import-data.https.html": [
     1014        "slow"
     1015    ],
     1016    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-import.http.html": [
     1017        "slow"
     1018    ],
     1019    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-import.https.html": [
     1020        "slow"
     1021    ],
     1022    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-module.http.html": [
     1023        "slow"
     1024    ],
     1025    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worker-module.https.html": [
     1026        "slow"
     1027    ],
     1028    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-animation-import-data.https.html": [
     1029        "slow"
     1030    ],
     1031    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-animation.https.html": [
     1032        "slow"
     1033    ],
     1034    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-audio-import-data.https.html": [
     1035        "slow"
     1036    ],
     1037    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-audio.https.html": [
     1038        "slow"
     1039    ],
     1040    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-layout-import-data.https.html": [
     1041        "slow"
     1042    ],
     1043    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-layout.https.html": [
     1044        "slow"
     1045    ],
     1046    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-paint-import-data.https.html": [
     1047        "slow"
     1048    ],
     1049    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-self/worklet-paint.https.html": [
     1050        "slow"
     1051    ],
     1052    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/script-tag.http.html": [
     1053        "slow"
     1054    ],
     1055    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/script-tag.https.html": [
     1056        "slow"
     1057    ],
     1058    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-classic.http.html": [
     1059        "slow"
     1060    ],
     1061    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-classic.https.html": [
     1062        "slow"
     1063    ],
     1064    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-import-data.http.html": [
     1065        "slow"
     1066    ],
     1067    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-import-data.https.html": [
     1068        "slow"
     1069    ],
     1070    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-import.http.html": [
     1071        "slow"
     1072    ],
     1073    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-import.https.html": [
     1074        "slow"
     1075    ],
     1076    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-module.http.html": [
     1077        "slow"
     1078    ],
     1079    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/sharedworker-module.https.html": [
     1080        "slow"
     1081    ],
     1082    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-classic.http.html": [
     1083        "slow"
     1084    ],
     1085    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-classic.https.html": [
     1086        "slow"
     1087    ],
     1088    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-import-data.http.html": [
     1089        "slow"
     1090    ],
     1091    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-import-data.https.html": [
     1092        "slow"
     1093    ],
     1094    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-import.http.html": [
     1095        "slow"
     1096    ],
     1097    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-import.https.html": [
     1098        "slow"
     1099    ],
     1100    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-module.http.html": [
     1101        "slow"
     1102    ],
     1103    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worker-module.https.html": [
     1104        "slow"
     1105    ],
     1106    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-animation-import-data.https.html": [
     1107        "slow"
     1108    ],
     1109    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-animation.https.html": [
     1110        "slow"
     1111    ],
     1112    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-audio-import-data.https.html": [
     1113        "slow"
     1114    ],
     1115    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-audio.https.html": [
     1116        "slow"
     1117    ],
     1118    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-layout-import-data.https.html": [
     1119        "slow"
     1120    ],
     1121    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-layout.https.html": [
     1122        "slow"
     1123    ],
     1124    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-paint-import-data.https.html": [
     1125        "slow"
     1126    ],
     1127    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/script-src-wildcard/worklet-paint.https.html": [
     1128        "slow"
     1129    ],
     1130    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/script-tag.http.html": [
     1131        "slow"
     1132    ],
     1133    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/script-tag.https.html": [
     1134        "slow"
     1135    ],
     1136    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-classic.http.html": [
     1137        "slow"
     1138    ],
     1139    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-classic.https.html": [
     1140        "slow"
     1141    ],
     1142    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-import-data.http.html": [
     1143        "slow"
     1144    ],
     1145    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-import-data.https.html": [
     1146        "slow"
     1147    ],
     1148    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-import.http.html": [
     1149        "slow"
     1150    ],
     1151    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-import.https.html": [
     1152        "slow"
     1153    ],
     1154    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-module.http.html": [
     1155        "slow"
     1156    ],
     1157    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/sharedworker-module.https.html": [
     1158        "slow"
     1159    ],
     1160    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-classic.http.html": [
     1161        "slow"
     1162    ],
     1163    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-classic.https.html": [
     1164        "slow"
     1165    ],
     1166    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-import-data.http.html": [
     1167        "slow"
     1168    ],
     1169    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-import-data.https.html": [
     1170        "slow"
     1171    ],
     1172    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-import.http.html": [
     1173        "slow"
     1174    ],
     1175    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-import.https.html": [
     1176        "slow"
     1177    ],
     1178    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-module.http.html": [
     1179        "slow"
     1180    ],
     1181    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worker-module.https.html": [
     1182        "slow"
     1183    ],
     1184    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-animation-import-data.https.html": [
     1185        "slow"
     1186    ],
     1187    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-animation.https.html": [
     1188        "slow"
     1189    ],
     1190    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-audio-import-data.https.html": [
     1191        "slow"
     1192    ],
     1193    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-audio.https.html": [
     1194        "slow"
     1195    ],
     1196    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-layout-import-data.https.html": [
     1197        "slow"
     1198    ],
     1199    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-layout.https.html": [
     1200        "slow"
     1201    ],
     1202    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-paint-import-data.https.html": [
     1203        "slow"
     1204    ],
     1205    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-none/worklet-paint.https.html": [
     1206        "slow"
     1207    ],
     1208    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/script-tag.http.html": [
     1209        "slow"
     1210    ],
     1211    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/script-tag.https.html": [
     1212        "slow"
     1213    ],
     1214    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-classic.http.html": [
     1215        "slow"
     1216    ],
     1217    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-classic.https.html": [
     1218        "slow"
     1219    ],
     1220    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-import-data.http.html": [
     1221        "slow"
     1222    ],
     1223    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-import-data.https.html": [
     1224        "slow"
     1225    ],
     1226    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-import.http.html": [
     1227        "slow"
     1228    ],
     1229    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-import.https.html": [
     1230        "slow"
     1231    ],
     1232    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-module.http.html": [
     1233        "slow"
     1234    ],
     1235    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/sharedworker-module.https.html": [
     1236        "slow"
     1237    ],
     1238    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-classic.http.html": [
     1239        "slow"
     1240    ],
     1241    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-classic.https.html": [
     1242        "slow"
     1243    ],
     1244    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-import-data.http.html": [
     1245        "slow"
     1246    ],
     1247    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-import-data.https.html": [
     1248        "slow"
     1249    ],
     1250    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-import.http.html": [
     1251        "slow"
     1252    ],
     1253    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-import.https.html": [
     1254        "slow"
     1255    ],
     1256    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-module.http.html": [
     1257        "slow"
     1258    ],
     1259    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worker-module.https.html": [
     1260        "slow"
     1261    ],
     1262    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-animation-import-data.https.html": [
     1263        "slow"
     1264    ],
     1265    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-animation.https.html": [
     1266        "slow"
     1267    ],
     1268    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-audio-import-data.https.html": [
     1269        "slow"
     1270    ],
     1271    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-audio.https.html": [
     1272        "slow"
     1273    ],
     1274    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-layout-import-data.https.html": [
     1275        "slow"
     1276    ],
     1277    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-layout.https.html": [
     1278        "slow"
     1279    ],
     1280    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-paint-import-data.https.html": [
     1281        "slow"
     1282    ],
     1283    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-self/worklet-paint.https.html": [
     1284        "slow"
     1285    ],
     1286    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/script-tag.http.html": [
     1287        "slow"
     1288    ],
     1289    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/script-tag.https.html": [
     1290        "slow"
     1291    ],
     1292    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-classic.http.html": [
     1293        "slow"
     1294    ],
     1295    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-classic.https.html": [
     1296        "slow"
     1297    ],
     1298    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-import-data.http.html": [
     1299        "slow"
     1300    ],
     1301    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-import-data.https.html": [
     1302        "slow"
     1303    ],
     1304    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-import.http.html": [
     1305        "slow"
     1306    ],
     1307    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-import.https.html": [
     1308        "slow"
     1309    ],
     1310    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-module.http.html": [
     1311        "slow"
     1312    ],
     1313    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/sharedworker-module.https.html": [
     1314        "slow"
     1315    ],
     1316    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-classic.http.html": [
     1317        "slow"
     1318    ],
     1319    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-classic.https.html": [
     1320        "slow"
     1321    ],
     1322    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-import-data.http.html": [
     1323        "slow"
     1324    ],
     1325    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-import-data.https.html": [
     1326        "slow"
     1327    ],
     1328    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-import.http.html": [
     1329        "slow"
     1330    ],
     1331    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-import.https.html": [
     1332        "slow"
     1333    ],
     1334    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-module.http.html": [
     1335        "slow"
     1336    ],
     1337    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worker-module.https.html": [
     1338        "slow"
     1339    ],
     1340    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-animation-import-data.https.html": [
     1341        "slow"
     1342    ],
     1343    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-animation.https.html": [
     1344        "slow"
     1345    ],
     1346    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-audio-import-data.https.html": [
     1347        "slow"
     1348    ],
     1349    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-audio.https.html": [
     1350        "slow"
     1351    ],
     1352    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-layout-import-data.https.html": [
     1353        "slow"
     1354    ],
     1355    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-layout.https.html": [
     1356        "slow"
     1357    ],
     1358    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-paint-import-data.https.html": [
     1359        "slow"
     1360    ],
     1361    "imported/w3c/web-platform-tests/content-security-policy/gen/top.meta/worker-src-wildcard/worklet-paint.https.html": [
    5761362        "slow"
    5771363    ],
Note: See TracChangeset for help on using the changeset viewer.