blob: 4a03aa6aa5e62ff2f5a0ff39b26529168ae5577c [file] [log] [blame]
CONSOLE MESSAGE: Refused to execute a script for an inline event handler because 'unsafe-inline' appears in neither the script-src directive nor the default-src directive of the Content Security Policy.
CONSOLE MESSAGE: PASS: clicked is 1
This test checks that if an inline handler was replaced with a JSFunction, CSP doesn't prevent it from being invoked. It passes if there is one SecurityError and 'PASS' message, with no 'FAIL' logs appearing.