OLD | NEW |
1 <!DOCTYPE html> | 1 <!DOCTYPE html> |
2 <html> | 2 <html> |
3 <head> | 3 <head> |
4 <script src="resources/report-test.js"></script> | 4 <script src="resources/report-test.js"></script> |
5 <meta http-equiv="Content-Security-Policy" content="img-src 'none'; report-u
ri /security/contentSecurityPolicy/resources/save-report.php"> | 5 <meta http-equiv="Content-Security-Policy" content="img-src 'none'; report-u
ri /security/contentSecurityPolicy/resources/save-report.php?test=report-same-or
igin-with-cookies.html"> |
6 </head> | 6 </head> |
7 <body> | 7 <body> |
8 <script> | 8 <script> |
9 var xhr = new XMLHttpRequest(); | 9 var xhr = new XMLHttpRequest(); |
10 xhr.open("GET", "/cookies/resources/setCookies.cgi", false); | 10 xhr.open("GET", "/cookies/resources/setCookies.cgi", false); |
11 xhr.setRequestHeader("SET-COOKIE", "cspViolationReportCookie=sameOrigin;path
=/"); | 11 xhr.setRequestHeader("SET-COOKIE", "cspViolationReportCookie=sameOrigin;path
=/"); |
12 xhr.send(null); | 12 xhr.send(null); |
13 </script> | 13 </script> |
14 | 14 |
15 <!-- This image will generate a CSP violation report. --> | 15 <!-- This image will generate a CSP violation report. --> |
16 <img src="/security/resources/abe.png"> | 16 <img src="/security/resources/abe.png"> |
17 | 17 |
18 <script src='resources/go-to-echo-report.js'></script> | 18 <script src='resources/go-to-echo-report.js'></script> |
19 </body> | 19 </body> |
20 </html> | 20 </html> |
OLD | NEW |