csp-script-src-self.html (598B)
1 <!DOCTYPE html> 2 3 <head> 4 <!-- disallow inline script --> 5 <meta http-equiv="Content-Security-Policy" content="script-src 'self' 'nonce-allowed-inline-script-for-test'"> 6 </head> 7 <script src="/common/utils.js"></script> 8 <script src="/resources/testharness.js"></script> 9 <script src="/resources/testharnessreport.js"></script> 10 <script src="utils.js"></script> 11 <script src="csp-script-src.js"></script> 12 <script nonce="allowed-inline-script-for-test"> 13 const searchParams = new URLSearchParams(location.search); 14 writeValueToServer(searchParams.get('key'), "csp is ignored unexpectedly"); 15 </script>