CONSOLE MESSAGE: The 'allow' directive has been replaced with 'default-src'. Please use that directive instead, as 'allow' has no effect. | |
CONSOLE MESSAGE: Refused to load http://localhost:8000/security/contentSecurityPolicy/resources/script.js because it appears in neither the script-src directive nor the default-src directive of the Content Security Policy. | |
This script should not execute even through the second CSP header would allow it. | |
-------- | |
Frame: '<!--frame1-->' | |
-------- | |
PASS |