blob: ea359571ac3d1edf88b7e57fef27b1c4bf83b050 [file] [log] [blame]
blob: URLs are same-origin with the page in which they were created, but explicitly do not match the 'self' or '*' source in CSP directives because they are more akin to 'unsafe-inline' content.
PASS Expecting logs: ["violated-directive=script-src-elem"]