blob: 244bff0194fa2497b15a8c1955e8d9457a5a9c31 [file] [log] [blame]
CONSOLE MESSAGE: The XSS Auditor refused to execute a script in ';%3c/script%3e' because its source code was found within the request. The server sent an 'X-XSS-Protection' header requesting this behavior.
CONSOLE MESSAGE: The XSS Auditor refused to execute a script in ';%3c/script%3e' because its source code was found within the request. The server sent an 'X-XSS-Protection' header requesting this behavior.
Check that an X-XSS-Protection header added by a 304 response does not override one from the original request.
On success, you will see a series of "PASS" messages, followed by "TEST COMPLETE".
Two console messages should be generated, noting that JavaScript was blocked.
Check that the nonce is the same, meaning that the document was only generated once:
PASS frame1.contentDocument.querySelector("input").value == frame2.contentDocument.querySelector("input").value is true
PASS successfullyParsed is true