2010-01-22 13:38:21 -08:00
|
|
|
<html>
|
|
|
|
<head>
|
|
|
|
<link rel='stylesheet' type='text/css'
|
2013-09-05 23:41:38 -07:00
|
|
|
href='http://example.org/tests/content/base/test/csp/file_CSP.sjs?testid=style_bad&type=text/css' />
|
2010-01-22 13:38:21 -08:00
|
|
|
<link rel='stylesheet' type='text/css'
|
|
|
|
href='file_CSP.sjs?testid=style_good&type=text/css' />
|
|
|
|
|
2012-08-30 10:58:24 -07:00
|
|
|
<!-- Used to embed inline styles here for testing fonts, but can't do that -->
|
|
|
|
<!-- due to bug 763879 (block inline styles). Moved these to an external, CSS -->
|
|
|
|
<!-- file (file_CSP.css). -->
|
|
|
|
<link rel='stylesheet' type='text/css' href='file_CSP.css' />
|
2010-01-22 13:38:21 -08:00
|
|
|
|
|
|
|
</head>
|
|
|
|
<body>
|
|
|
|
<!-- these should be stopped by CSP. :) -->
|
2013-09-05 23:41:38 -07:00
|
|
|
<img src="http://example.org/tests/content/base/test/csp/file_CSP.sjs?testid=img_bad&type=img/png"> </img>
|
|
|
|
<audio src="http://example.org/tests/content/base/test/csp/file_CSP.sjs?testid=media_bad&type=audio/vorbis"></audio>
|
|
|
|
<script src='http://example.org/tests/content/base/test/csp/file_CSP.sjs?testid=script_bad&type=text/javascript'></script>
|
|
|
|
<iframe src='http://example.org/tests/content/base/test/csp/file_CSP.sjs?testid=frame_bad&content=FAIL'></iframe>
|
2010-01-22 13:38:21 -08:00
|
|
|
<object width="10" height="10">
|
2013-09-05 23:41:38 -07:00
|
|
|
<param name="movie" value="http://example.org/tests/content/base/test/csp/file_CSP.sjs?testid=object_bad&type=application/x-shockwave-flash">
|
|
|
|
<embed src="http://example.org/tests/content/base/test/csp/file_CSP.sjs?testid=object_bad&type=application/x-shockwave-flash"></embed>
|
2010-01-22 13:38:21 -08:00
|
|
|
</object>
|
|
|
|
|
|
|
|
<!-- these should load ok. :) -->
|
|
|
|
<img src="file_CSP.sjs?testid=img_good&type=img/png" />
|
|
|
|
<audio src="file_CSP.sjs?testid=media_good&type=audio/vorbis"></audio>
|
|
|
|
<script src='file_CSP.sjs?testid=script_good&type=text/javascript'></script>
|
|
|
|
<iframe src='file_CSP.sjs?testid=frame_good&content=PASS'></iframe>
|
|
|
|
|
|
|
|
<object width="10" height="10">
|
|
|
|
<param name="movie" value="file_CSP.sjs?testid=object_good&type=application/x-shockwave-flash">
|
|
|
|
<embed src="file_CSP.sjs?testid=object_good&type=application/x-shockwave-flash"></embed>
|
|
|
|
</object>
|
|
|
|
|
|
|
|
<!-- XHR tests... they're taken care of in this script,
|
|
|
|
and since the URI doesn't have any 'testid' values,
|
|
|
|
it will just be ignored by the test framework. -->
|
|
|
|
<script src='file_CSP_main.js'></script>
|
|
|
|
|
|
|
|
<!-- Support elements for the @font-face test -->
|
|
|
|
<div class="div_arbitrary_good">arbitrary good</div>
|
|
|
|
<div class="div_arbitrary_bad">arbitrary_bad</div>
|
|
|
|
</body>
|
|
|
|
</html>
|