blob: 78b9f61ace7c7ca59e0716702664ce797e5640f1 [file] [log] [blame]
<html>
<body>
<script>
if (window.testRunner) {
testRunner.dumpAsText();
testRunner.dumpFrameLoadCallbacks();
}
</script>
<p>This test loads a secure iframe that loads an insecure style sheet.
We should trigger a mixed content callback because an active network attacker
can use CSS3 to breach the confidentiality of the HTTPS security origin.</p>
<iframe src="https://127.0.0.1:8443/security/mixedContent/resources/frame-with-insecure-css.html";
></iframe>
</body>
</html>