blob: bdf7bb7ff8dd40f992b41b684430ad890c9b6ee4 [file] [log] [blame]
<!DOCTYPE html>
if (window.testRunner)
<p>This test loads a secure iframe that loads an insecure image inside a blob URL iframe.
A blob URL created in a secure context is considered secure. We should trigger a mixed content
block because the blob URL grandchild iframe inherited the CSP directive block-all-mixed-content
from the child frame. This test PASSED if the grandchild iframe is filled solid green.
Otherwise, it FAILED.</p>
<iframe src="" width="100%" height="300"></iframe>