| CONSOLE MESSAGE: line 1: Unsafe JavaScript attempt to access frame with URL http://localhost:8000/security/dataURL/resources/foreign-domain-data-url-window-location.html from frame with URL http://127.0.0.1:8000/security/dataURL/xss-DENIED-to-data-url-in-foriegn-domain-subframe-location-change.html. Domains, protocols and ports must match. |
| |
| Opener frame |
| |
| |
| PASS: Cross frame access to a data: URL embed in a frame on a foreign domain denied! |
| |
| |
| -------- |
| Frame: '<!--framePath //<!--frame0-->-->' |
| -------- |
| PASS: Cross frame access from a frame on a foreign domain denied! |
| |
| Inner iframe. This iframe (which is data: URL and whose parent is on a foreign domain) is the frame that the main frame is trying to access. It should not have access to it. |
| |
| |
| |
| -------- |
| Frame: 'flag' |
| -------- |
| |