Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(14)

Side by Side Diff: LayoutTests/http/tests/security/XFrameOptions/x-frame-options-ancestors-same-origin-deny-expected.txt

Issue 20822002: 'X-Frame-Options: SAMEORIGIN' should check all ancestor frames. (Closed) Base URL: svn://svn.chromium.org/blink/trunk
Patch Set: tests. Created 7 years, 5 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch | Annotate | Revision Log
OLDNEW
(Empty)
1 http://localhost:8000/security/XFrameOptions/resources/x-frame-options-parent-sa me-origin-ancestor.html - willSendRequest <NSURLRequest URL http://localhost:800 0/security/XFrameOptions/resources/x-frame-options-parent-same-origin-ancestor.h tml, main document URL http://127.0.0.1:8000/security/XFrameOptions/x-frame-opti ons-ancestors-same-origin-deny.html, http method GET> redirectResponse (null)
2 http://localhost:8000/security/XFrameOptions/resources/x-frame-options-parent-sa me-origin-ancestor.html - didReceiveResponse <NSURLResponse http://localhost:800 0/security/XFrameOptions/resources/x-frame-options-parent-same-origin-ancestor.h tml, http status code 200>
3 http://localhost:8000/security/XFrameOptions/resources/x-frame-options-parent-sa me-origin-ancestor.html - didFinishLoading
4 http://127.0.0.1:8000/security/XFrameOptions/resources/x-frame-options-parent-sa me-origin-deny.cgi - willSendRequest <NSURLRequest URL http://127.0.0.1:8000/sec urity/XFrameOptions/resources/x-frame-options-parent-same-origin-deny.cgi, main document URL http://127.0.0.1:8000/security/XFrameOptions/x-frame-options-ancest ors-same-origin-deny.html, http method GET> redirectResponse (null)
5 CONSOLE MESSAGE: Refused to display 'http://127.0.0.1:8000/security/XFrameOption s/resources/x-frame-options-parent-same-origin-deny.cgi' in a frame because it s et 'X-Frame-Options' to 'sameorigin'.
6 This tests verifies that 'X-Frame-Options: SAMEORIGIN' blocks sameorigin.com -> crossorigin.com -> sameorigin.com ancestor chains.
7
8 There should be content in the iframe below, but not in its child frame.
9
10
11
12 --------
13 Frame: '<!--framePath //<!--frame0-->-->'
14 --------
15 The inner frame should not render any content, as this frame is cross-origin.
16
17
18
19 --------
20 Frame: '<!--framePath //<!--frame0-->/<!--frame0-->-->'
21 --------
22
OLDNEW

Powered by Google App Engine
This is Rietveld 408576698