to-javascript-url-frame-src.html (427B)
1 <!DOCTYPE html> 2 <script src="/resources/testharness.js"></script> 3 <script src="/resources/testharnessreport.js"></script> 4 5 <meta http-equiv="Content-Security-Policy" content="frame-src 'none'"> 6 7 <body> 8 9 <script> 10 var t = async_test("<iframe src='javascript:...'> not blocked by 'frame-src'"); 11 12 var i = document.createElement('iframe'); 13 i.src = "javascript:window.top.t.done();"; 14 15 document.body.appendChild(i); 16 </script>