blob: URLs are same-origin with the page in which they were created, but explicitly do not match the 'self' or '*' source in CSP directives because they are more akin to 'unsafe-inline' content. | |
PASS Expecting logs: ["violated-directive=script-src-elem"] | |