<!DOCTYPE html> | |
<html> | |
<head> | |
<meta http-equiv="Content-Security-Policy" content="script-src 'unsafe-inline'"/> | |
<script> | |
if (window.testRunner) { | |
testRunner.dumpAsText(); | |
} | |
</script> | |
</head> | |
<body> | |
<script> | |
try { | |
var worker = new Worker('http://127.0.0.1:8000/security/contentSecurityPolicy/resources/worker.php?type=alert-pass&csp=' + | |
encodeURIComponent("script-src 'self' 'unsafe-inline'")); | |
alert("PASS"); | |
} catch (e) { | |
alert(e); | |
} | |
</script> | |
</body> | |
</html> |