file_bug941404.html (790B)
1 <html> 2 <head> <meta charset="utf-8"> </head> 3 <body> 4 5 <!-- this should be allowed (no CSP)--> 6 <img src="http://example.org/tests/dom/security/test/csp/file_CSP.sjs?testid=img_good&type=img/png"> </img> 7 8 9 <script type="text/javascript"> 10 var req = new XMLHttpRequest(); 11 req.onload = function() { 12 //this should be allowed (no CSP) 13 try { 14 var img = document.createElement("img"); 15 img.src="http://example.org/tests/dom/security/test/csp/file_CSP.sjs?testid=img2_good&type=img/png"; 16 document.body.appendChild(img); 17 } catch(e) { 18 console.log("yo: "+e); 19 } 20 }; 21 req.open("get", "file_bug941404_xhr.html", true); 22 req.responseType = "document"; 23 req.send(); 24 </script> 25 26 </body> 27 </html>