content-security-policy: Complete Failures

Completely failed files: 384; Completely failed subtests: 158; Failure level: 158/911 (17.34%)

Test Files

  1. /content-security-policy/style-src-attr-elem/style-src-attr-blocked-src-allowed.html (1/2, 50.00%, 0.11% of total)
  2. /content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-same-url-allow.html (1/1, 100.00%, 0.11% of total)
  3. /content-security-policy/securitypolicyviolation/upgrade-insecure-requests-reporting.https.html (3/3, 100.00%, 0.33% of total)
  4. /content-security-policy/frame-ancestors/frame-ancestors-nested-same-in-cross-url-block.html (1/1, 100.00%, 0.11% of total)
  5. /content-security-policy/securitypolicyviolation/img-src-redirect-upgrade-reporting.https.html (1/1, 100.00%, 0.11% of total)
  6. /content-security-policy/navigate-to/form-cross-origin-blocked.sub.html (2/2, 100.00%, 0.22% of total)
  7. /content-security-policy/frame-ancestors/frame-ancestors-nested-same-in-same-url-block.html (1/1, 100.00%, 0.11% of total)
  8. /content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-same-star-allow.html (1/1, 100.00%, 0.11% of total)
  9. /content-security-policy/navigate-to/href-location-cross-origin-allowed.sub.html (1/1, 100.00%, 0.11% of total)
  10. /content-security-policy/navigation/javascript-url-navigation-inherits-csp.html (1/1, 100.00%, 0.11% of total)
  11. /content-security-policy/navigate-to/link-click-redirected-blocked.sub.html (2/2, 100.00%, 0.22% of total)
  12. /content-security-policy/style-src-attr-elem/style-src-elem-allowed-attr-blocked.html (1/2, 50.00%, 0.11% of total)
  13. /content-security-policy/navigate-to/parent-navigates-child-blocked.html (2/2, 100.00%, 0.22% of total)
  14. /content-security-policy/securitypolicyviolation/inside-service-worker.https.html (1/1, 100.00%, 0.11% of total)
  15. /content-security-policy/frame-ancestors/frame-ancestors-nested-same-in-cross-self-block.html (1/1, 100.00%, 0.11% of total)
  16. /content-security-policy/style-src-attr-elem/style-src-attr-allowed-src-blocked.html (1/1, 100.00%, 0.11% of total)
  17. /content-security-policy/script-src/hash-always-converted-to-utf-8/iso-8859-7.html (1/1, 100.00%, 0.11% of total)
  18. /content-security-policy/navigate-to/link-click-cross-origin-blocked.sub.html (2/2, 100.00%, 0.22% of total)
  19. /content-security-policy/frame-ancestors/frame-ancestors-self-block.html (1/1, 100.00%, 0.11% of total)
  20. /content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-cross-self-block.html (1/1, 100.00%, 0.11% of total)
  21. /content-security-policy/securitypolicyviolation/inside-dedicated-worker.html (1/1, 100.00%, 0.11% of total)
  22. /content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-same-url-block.html (1/1, 100.00%, 0.11% of total)
  23. /content-security-policy/unsafe-hashes/style_attribute_allowed.html (1/1, 100.00%, 0.11% of total)
  24. /content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-cross-url-block.html (1/1, 100.00%, 0.11% of total)
  25. /content-security-policy/media-src/media-src-redir-bug.sub.html (5/5, 100.00%, 0.55% of total)
  26. /content-security-policy/script-src-attr-elem/script-src-attr-blocked-src-allowed.html (1/1, 100.00%, 0.11% of total)
  27. /content-security-policy/style-src-attr-elem/style-src-elem-blocked-attr-allowed.html (2/2, 100.00%, 0.22% of total)
  28. /content-security-policy/securitypolicyviolation/blockeduri-eval.html (1/1, 100.00%, 0.11% of total)
  29. /content-security-policy/securitypolicyviolation/inside-shared-worker.html (1/3, 33.33%, 0.11% of total)
  30. /content-security-policy/navigate-to/meta-refresh-redirected-blocked.sub.html (2/2, 100.00%, 0.22% of total)
  31. /content-security-policy/navigate-to/spv-only-sent-to-initiator.sub.html (1/2, 50.00%, 0.11% of total)
  32. /content-security-policy/reporting/report-same-origin-with-cookies.html (1/3, 33.33%, 0.11% of total)
  33. /content-security-policy/media-src/media-src-7_2.html (3/3, 100.00%, 0.33% of total)
  34. /content-security-policy/unsafe-hashes/javascript_src_denied_missing_unsafe_hashes-window_location.html (1/1, 100.00%, 0.11% of total)
  35. /content-security-policy/media-src/media-src-7_3.sub.html (2/2, 100.00%, 0.22% of total)
  36. /content-security-policy/navigate-to/href-location-redirected-allowed.html (1/1, 100.00%, 0.11% of total)
  37. /content-security-policy/script-src/hash-always-converted-to-utf-8/iso-8859-9.html (1/1, 100.00%, 0.11% of total)
  38. /content-security-policy/script-src-attr-elem/script-src-elem-blocked-attr-allowed.html (1/2, 50.00%, 0.11% of total)
  39. /content-security-policy/connect-src/worker-from-guid.sub.html (1/1, 100.00%, 0.11% of total)
  40. /content-security-policy/navigate-to/link-click-blocked.sub.html (2/2, 100.00%, 0.22% of total)
  41. /content-security-policy/sandbox/window-reuse-sandboxed.html (1/1, 100.00%, 0.11% of total)
  42. /content-security-policy/navigate-to/form-redirected-blocked.sub.html (2/2, 100.00%, 0.22% of total)
  43. /content-security-policy/securitypolicyviolation/idlharness.window.html (8/41, 19.51%, 0.88% of total)
  44. /content-security-policy/script-src/hash-always-converted-to-utf-8/iso-8859-1.html (1/1, 100.00%, 0.11% of total)
  45. /content-security-policy/unsafe-eval/eval-blocked-in-about-blank-iframe.sub.html (1/1, 100.00%, 0.11% of total)
  46. /content-security-policy/navigate-to/href-location-cross-origin-blocked.sub.html (2/2, 100.00%, 0.22% of total)
  47. /content-security-policy/frame-ancestors/frame-ancestors-star-allow-crossorigin.html (1/1, 100.00%, 0.11% of total)
  48. /content-security-policy/navigate-to/form-blocked.sub.html (2/2, 100.00%, 0.22% of total)
  49. /content-security-policy/script-src/script-src-1_10.html (1/2, 50.00%, 0.11% of total)
  50. /content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-cross-url-allow.html (1/1, 100.00%, 0.11% of total)
  51. /content-security-policy/navigate-to/meta-refresh-blocked.sub.html (2/2, 100.00%, 0.22% of total)
  52. /content-security-policy/script-src-attr-elem/script-src-elem-allowed-attr-blocked.html (1/2, 50.00%, 0.11% of total)
  53. /content-security-policy/script-src/hash-always-converted-to-utf-8/iso-8859-3.html (1/1, 100.00%, 0.11% of total)
  54. /content-security-policy/plugin-types/plugintypes-mismatched-url.html (1/1, 100.00%, 0.11% of total)
  55. /content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-same-self-block.html (1/1, 100.00%, 0.11% of total)
  56. /content-security-policy/script-src/worker-set-timeout-blocked.sub.html (1/1, 100.00%, 0.11% of total)
  57. /content-security-policy/frame-ancestors/frame-ancestors-nested-same-in-cross-none-block.html (1/1, 100.00%, 0.11% of total)
  58. /content-security-policy/embedded-enforcement/required_csp-header.html (25/70, 35.71%, 2.74% of total)
  59. /content-security-policy/navigate-to/href-location-redirected-blocked.sub.html (2/2, 100.00%, 0.22% of total)
  60. /content-security-policy/frame-ancestors/frame-ancestors-none-block.html (1/1, 100.00%, 0.11% of total)
  61. /content-security-policy/style-src/inline-style-attribute-allowed.sub.html (1/1, 100.00%, 0.11% of total)
  62. /content-security-policy/style-src/inline-style-allowed-while-cloning-objects.sub.html (1/1, 100.00%, 0.11% of total)
  63. /content-security-policy/script-src/script-src-strict_dynamic_in_img-src.html (1/1, 100.00%, 0.11% of total)
  64. /content-security-policy/style-src-attr-elem/style-src-elem-allowed-src-blocked.html (1/1, 100.00%, 0.11% of total)
  65. /content-security-policy/style-src/style-blocked.sub.html (1/1, 100.00%, 0.11% of total)
  66. /content-security-policy/frame-ancestors/frame-ancestors-nested-same-in-same-none-block.html (1/1, 100.00%, 0.11% of total)
  67. /content-security-policy/prefetch-src/prefetch-allowed.html (1/3, 33.33%, 0.11% of total)
  68. /content-security-policy/style-src-attr-elem/style-src-elem-blocked-src-allowed.html (2/2, 100.00%, 0.22% of total)
  69. /content-security-policy/script-src/worker-importscripts-blocked.sub.html (1/2, 50.00%, 0.11% of total)
  70. /content-security-policy/frame-ancestors/frame-ancestors-nested-same-in-cross-url-allow.html (1/1, 100.00%, 0.11% of total)
  71. /content-security-policy/plugin-types/plugintypes-mismatched-data.html (1/1, 100.00%, 0.11% of total)
  72. /content-security-policy/connect-src/worker-connect-src-blocked.sub.html (1/1, 100.00%, 0.11% of total)
  73. /content-security-policy/prefetch-src/prefetch-header-blocked.html (1/3, 33.33%, 0.11% of total)
  74. /content-security-policy/form-action/form-action-src-redirect-blocked.sub.html (1/1, 100.00%, 0.11% of total)
  75. /content-security-policy/navigate-to/href-location-allowed.html (1/1, 100.00%, 0.11% of total)
  76. /content-security-policy/reporting-api/reporting-api-sends-reports-on-violation.https.sub.html (1/3, 33.33%, 0.11% of total)
  77. /content-security-policy/reporting-api/reporting-api-works-on-frame-src.https.sub.html (1/2, 50.00%, 0.11% of total)
  78. /content-security-policy/inside-worker/shared-inheritance.html (3/15, 20.00%, 0.33% of total)
  79. /content-security-policy/navigate-to/unsafe-allow-redirects/blocked-end-of-chain.sub.html (1/1, 100.00%, 0.11% of total)
  80. /content-security-policy/navigate-to/href-location-blocked.sub.html (2/2, 100.00%, 0.22% of total)
  81. /content-security-policy/media-src/media-src-7_1.html (3/3, 100.00%, 0.33% of total)
  82. /content-security-policy/media-src/media-src-blocked.sub.html (1/5, 20.00%, 0.11% of total)
  83. /content-security-policy/navigate-to/child-navigates-parent-blocked.sub.html (2/2, 100.00%, 0.22% of total)
  84. /content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-sandboxed-cross-url-block.html (1/1, 100.00%, 0.11% of total)
  85. /content-security-policy/unsafe-hashes/javascript_src_allowed-window_location.html (1/1, 100.00%, 0.11% of total)
  86. /content-security-policy/prefetch-src/prefetch-blocked.html (1/3, 33.33%, 0.11% of total)
  87. /content-security-policy/navigate-to/meta-refresh-cross-origin-blocked.sub.html (2/2, 100.00%, 0.22% of total)
  88. /content-security-policy/frame-ancestors/frame-ancestors-nested-same-in-cross-star-allow.html (1/1, 100.00%, 0.11% of total)
  89. /content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-cross-none-block.html (1/1, 100.00%, 0.11% of total)
  90. /content-security-policy/frame-ancestors/frame-ancestors-url-block.html (1/1, 100.00%, 0.11% of total)
  91. /content-security-policy/sandbox/window-reuse-unsandboxed.html (1/1, 100.00%, 0.11% of total)
  92. /content-security-policy/unsafe-hashes/javascript_src_denied_wrong_hash-window_location.html (1/1, 100.00%, 0.11% of total)
  93. /content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-same-none-block.html (1/1, 100.00%, 0.11% of total)
  94. /content-security-policy/inheritance/window.html (4/4, 100.00%, 0.44% of total)
  95. /content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-cross-star-allow.html (1/1, 100.00%, 0.11% of total)
Test Show/Hide MessagesCh73
/content-security-policy/style-src-attr-elem/style-src-attr-blocked-src-allowed.html (1/2, 50.00%, 0.11% of total)TIMEOUT
Should fire a security policy violation eventNOTRUN
/content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-same-url-allow.html (1/1, 100.00%, 0.11% of total)TIMEOUT
A 'frame-ancestors' CSP directive with a URL value should block or allow rendering in nested frames as appropriate.NOTRUN
/content-security-policy/securitypolicyviolation/upgrade-insecure-requests-reporting.https.html (3/3, 100.00%, 0.33% of total)OK
Navigated iframe is upgraded and reportedFAIL
Upgraded iframe is reportedFAIL
Upgraded image is reportedFAIL
/content-security-policy/frame-ancestors/frame-ancestors-nested-same-in-cross-url-block.html (1/1, 100.00%, 0.11% of total)TIMEOUT
A 'frame-ancestors' CSP directive with a URL value should block or allow rendering in nested frames as appropriate.NOTRUN
/content-security-policy/securitypolicyviolation/img-src-redirect-upgrade-reporting.https.html (1/1, 100.00%, 0.11% of total)TIMEOUT
Image that redirects to http:// URL prohibited by Report-Only must generate a violation report, even with upgrade-insecure-requestsTIMEOUT
/content-security-policy/navigate-to/form-cross-origin-blocked.sub.html (2/2, 100.00%, 0.22% of total)OK
Test that the child iframe navigation is not allowedFAIL
Violation report status OK.FAIL
/content-security-policy/frame-ancestors/frame-ancestors-nested-same-in-same-url-block.html (1/1, 100.00%, 0.11% of total)OK
A 'frame-ancestors' CSP directive with a URL value should block or allow rendering in nested frames as appropriate.FAIL
/content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-same-star-allow.html (1/1, 100.00%, 0.11% of total)TIMEOUT
A 'frame-ancestors' CSP directive with a value '*' should render in nested frames.NOTRUN
/content-security-policy/navigate-to/href-location-cross-origin-allowed.sub.html (1/1, 100.00%, 0.11% of total)TIMEOUT
Test that the child iframe navigation is allowedNOTRUN
/content-security-policy/navigation/javascript-url-navigation-inherits-csp.html (1/1, 100.00%, 0.11% of total)OK
javascript-url-navigation-inherits-cspFAIL
/content-security-policy/navigate-to/link-click-redirected-blocked.sub.html (2/2, 100.00%, 0.22% of total)OK
Test that the child iframe navigation is not allowedFAIL
Violation report status OK.FAIL
/content-security-policy/style-src-attr-elem/style-src-elem-allowed-attr-blocked.html (1/2, 50.00%, 0.11% of total)TIMEOUT
Should fire a security policy violation for the attributeNOTRUN
/content-security-policy/navigate-to/parent-navigates-child-blocked.html (2/2, 100.00%, 0.22% of total)OK
Test that the parent can't navigate the child because the relevant policy belongs to the navigation initiator (in this case the parent, which has the policy `navigate-to support/wait_for_navigation.html;`)FAIL
Violation report status OK.FAIL
/content-security-policy/securitypolicyviolation/inside-service-worker.https.html (1/1, 100.00%, 0.11% of total)TIMEOUT
undefinedTIMEOUT
/content-security-policy/frame-ancestors/frame-ancestors-nested-same-in-cross-self-block.html (1/1, 100.00%, 0.11% of total)TIMEOUT
A 'frame-ancestors' CSP directive with a value 'same' should block render in same-origin nested frames.NOTRUN
/content-security-policy/style-src-attr-elem/style-src-attr-allowed-src-blocked.html (1/1, 100.00%, 0.11% of total)TIMEOUT
undefinedTIMEOUT
/content-security-policy/script-src/hash-always-converted-to-utf-8/iso-8859-7.html (1/1, 100.00%, 0.11% of total)OK
Should convert the script contents to UTF-8 before hashingFAIL
/content-security-policy/navigate-to/link-click-cross-origin-blocked.sub.html (2/2, 100.00%, 0.22% of total)OK
Test that the child iframe navigation is not allowedFAIL
Violation report status OK.FAIL
/content-security-policy/frame-ancestors/frame-ancestors-self-block.html (1/1, 100.00%, 0.11% of total)TIMEOUT
A 'frame-ancestors' CSP directive with a value 'self' should block rendering.NOTRUN
/content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-cross-self-block.html (1/1, 100.00%, 0.11% of total)TIMEOUT
A 'frame-ancestors' CSP directive with a value 'same' should block render in same-origin nested frames.NOTRUN
/content-security-policy/securitypolicyviolation/inside-dedicated-worker.html (1/1, 100.00%, 0.11% of total)TIMEOUT
undefinedTIMEOUT
/content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-same-url-block.html (1/1, 100.00%, 0.11% of total)TIMEOUT
A 'frame-ancestors' CSP directive with a URL value should block or allow rendering in nested frames as appropriate.NOTRUN
/content-security-policy/unsafe-hashes/style_attribute_allowed.html (1/1, 100.00%, 0.11% of total)OK
Test that the inline style attribute is loadedFAIL
/content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-cross-url-block.html (1/1, 100.00%, 0.11% of total)TIMEOUT
A 'frame-ancestors' CSP directive with a URL value should block or allow rendering in nested frames as appropriate.NOTRUN
/content-security-policy/media-src/media-src-redir-bug.sub.html (5/5, 100.00%, 0.55% of total)TIMEOUT
In-policy async video source elementNOTRUN
In-policy async video source element w/redirNOTRUN
In-policy async video srcNOTRUN
Should not fire policy violation eventsNOTRUN
in-policy async video src w/redirNOTRUN
/content-security-policy/script-src-attr-elem/script-src-attr-blocked-src-allowed.html (1/1, 100.00%, 0.11% of total)TIMEOUT
Should fire a security policy violation eventNOTRUN
/content-security-policy/style-src-attr-elem/style-src-elem-blocked-attr-allowed.html (2/2, 100.00%, 0.22% of total)TIMEOUT
Should fire a security policy violation for the inline blockNOTRUN
The inline style should not be applied and the attribute style should be appliedFAIL
/content-security-policy/securitypolicyviolation/blockeduri-eval.html (1/1, 100.00%, 0.11% of total)OK
Eval violations have a blockedURI of 'eval'FAIL
/content-security-policy/securitypolicyviolation/inside-shared-worker.html (1/3, 33.33%, 0.11% of total)TIMEOUT
SecurityPolicyViolation event fired on global with the correct blockedURI.TIMEOUT
/content-security-policy/navigate-to/meta-refresh-redirected-blocked.sub.html (2/2, 100.00%, 0.22% of total)OK
Test that the child iframe navigation is not allowedFAIL
Violation report status OK.FAIL
/content-security-policy/navigate-to/spv-only-sent-to-initiator.sub.html (1/2, 50.00%, 0.11% of total)TIMEOUT
Test that no spv event is raisedNOTRUN
/content-security-policy/reporting/report-same-origin-with-cookies.html (1/3, 33.33%, 0.11% of total)OK
Test report cookies.FAIL
/content-security-policy/media-src/media-src-7_2.html (3/3, 100.00%, 0.33% of total)TIMEOUT
In-policy audio source elementNOTRUN
In-policy audio srcNOTRUN
Should not fire policy violation eventsNOTRUN
/content-security-policy/unsafe-hashes/javascript_src_denied_missing_unsafe_hashes-window_location.html (1/1, 100.00%, 0.11% of total)TIMEOUT
Test that the javascript: src is not allowed to runNOTRUN
/content-security-policy/media-src/media-src-7_3.sub.html (2/2, 100.00%, 0.22% of total)TIMEOUT
In-policy track elementNOTRUN
Should not fire policy violation eventsNOTRUN
/content-security-policy/navigate-to/href-location-redirected-allowed.html (1/1, 100.00%, 0.11% of total)TIMEOUT
Test that the child iframe navigation is allowedNOTRUN
/content-security-policy/script-src/hash-always-converted-to-utf-8/iso-8859-9.html (1/1, 100.00%, 0.11% of total)OK
Should convert the script contents to UTF-8 before hashingFAIL
/content-security-policy/script-src-attr-elem/script-src-elem-blocked-attr-allowed.html (1/2, 50.00%, 0.11% of total)TIMEOUT
Should fire a security policy violation for the attributeNOTRUN
/content-security-policy/connect-src/worker-from-guid.sub.html (1/1, 100.00%, 0.11% of total)OK
Expecting logs: ["violated-directive=connect-src","xhr blocked","TEST COMPLETE"]FAIL
/content-security-policy/navigate-to/link-click-blocked.sub.html (2/2, 100.00%, 0.22% of total)OK
Test that the child iframe navigation is not allowedFAIL
Violation report status OK.FAIL
/content-security-policy/sandbox/window-reuse-sandboxed.html (1/1, 100.00%, 0.11% of total)TIMEOUT
Window object should not be reusedNOTRUN
/content-security-policy/navigate-to/form-redirected-blocked.sub.html (2/2, 100.00%, 0.22% of total)OK
Test that the child iframe navigation is not allowedFAIL
Violation report status OK.FAIL
/content-security-policy/securitypolicyviolation/idlharness.window.html (8/41, 19.51%, 0.88% of total)OK
SecurityPolicyViolationEvent interface: attribute blockedURLFAIL
SecurityPolicyViolationEvent interface: attribute colnoFAIL
SecurityPolicyViolationEvent interface: attribute documentURLFAIL
SecurityPolicyViolationEvent interface: attribute linenoFAIL
SecurityPolicyViolationEvent interface: new SecurityPolicyViolationEvent("securitypolicyviolation") must inherit property "blockedURL" with the proper typeFAIL
SecurityPolicyViolationEvent interface: new SecurityPolicyViolationEvent("securitypolicyviolation") must inherit property "colno" with the proper typeFAIL
SecurityPolicyViolationEvent interface: new SecurityPolicyViolationEvent("securitypolicyviolation") must inherit property "documentURL" with the proper typeFAIL
SecurityPolicyViolationEvent interface: new SecurityPolicyViolationEvent("securitypolicyviolation") must inherit property "lineno" with the proper typeFAIL
/content-security-policy/script-src/hash-always-converted-to-utf-8/iso-8859-1.html (1/1, 100.00%, 0.11% of total)OK
Should convert the script contents to UTF-8 before hashingFAIL
/content-security-policy/unsafe-eval/eval-blocked-in-about-blank-iframe.sub.html (1/1, 100.00%, 0.11% of total)OK
Expecting logs: ["violated-directive=script-src","PASS"]FAIL
/content-security-policy/navigate-to/href-location-cross-origin-blocked.sub.html (2/2, 100.00%, 0.22% of total)TIMEOUT
Test that the child iframe navigation is not allowedNOTRUN
Violation report status OK.FAIL
/content-security-policy/frame-ancestors/frame-ancestors-star-allow-crossorigin.html (1/1, 100.00%, 0.11% of total)OK
A 'frame-ancestors' CSP directive with '*' should allow rendering.FAIL
/content-security-policy/navigate-to/form-blocked.sub.html (2/2, 100.00%, 0.22% of total)OK
Test that the child iframe navigation is not allowedFAIL
Violation report status OK.FAIL
/content-security-policy/script-src/script-src-1_10.html (1/2, 50.00%, 0.11% of total)OK
Test that securitypolicyviolation event is firedFAIL
/content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-cross-url-allow.html (1/1, 100.00%, 0.11% of total)TIMEOUT
A 'frame-ancestors' CSP directive with a URL value should block or allow rendering in nested frames as appropriate.NOTRUN
/content-security-policy/navigate-to/meta-refresh-blocked.sub.html (2/2, 100.00%, 0.22% of total)OK
Test that the child iframe navigation is not allowedFAIL
Violation report status OK.FAIL
/content-security-policy/script-src-attr-elem/script-src-elem-allowed-attr-blocked.html (1/2, 50.00%, 0.11% of total)TIMEOUT
Should fire a security policy violation for the attributeNOTRUN
/content-security-policy/script-src/hash-always-converted-to-utf-8/iso-8859-3.html (1/1, 100.00%, 0.11% of total)OK
Should convert the script contents to UTF-8 before hashingFAIL
/content-security-policy/plugin-types/plugintypes-mismatched-url.html (1/1, 100.00%, 0.11% of total)TIMEOUT
Should not load the object because its declared type does not match its actual typeNOTRUN
/content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-same-self-block.html (1/1, 100.00%, 0.11% of total)TIMEOUT
A 'frame-ancestors' CSP directive with a value 'same' should block render in same-origin nested frames.NOTRUN
/content-security-policy/script-src/worker-set-timeout-blocked.sub.html (1/1, 100.00%, 0.11% of total)OK
Expecting alerts: ["setTimeout blocked"]FAIL
/content-security-policy/frame-ancestors/frame-ancestors-nested-same-in-cross-none-block.html (1/1, 100.00%, 0.11% of total)TIMEOUT
A 'frame-ancestors' CSP directive with a value 'none' should block rendering in nested frames.NOTRUN
/content-security-policy/embedded-enforcement/required_csp-header.html (25/70, 35.71%, 2.74% of total)TIMEOUT
Test cross origin redirect: Send Sec-Required-CSP Header on change of `src` attribute on iframe.TIMEOUT
Test cross origin redirect: Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - comma separatedTIMEOUT
Test cross origin redirect: Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - gibberish cspTIMEOUT
Test cross origin redirect: Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - html encoded stringTIMEOUT
Test cross origin redirect: Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - missing semicolonTIMEOUT
Test cross origin redirect: Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - misspeled 'none'TIMEOUT
Test cross origin redirect: Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - query values in pathTIMEOUT
Test cross origin redirect: Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - report-to presentTIMEOUT
Test cross origin redirect: Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - report-uri presentTIMEOUT
Test cross origin redirect: Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - unknown policy nameTIMEOUT
Test cross origin redirect: Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - unknown policy name in multiple directivesTIMEOUT
Test cross origin redirect: Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - url encoded stringTIMEOUT
Test same origin redirect: Send Sec-Required-CSP Header on change of `src` attribute on iframe.TIMEOUT
Test same origin redirect: Send Sec-Required-CSP when `csp` attribute of <iframe> is not empty.TIMEOUT
Test same origin redirect: Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - comma separatedTIMEOUT
Test same origin redirect: Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - gibberish cspTIMEOUT
Test same origin redirect: Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - html encoded stringTIMEOUT
Test same origin redirect: Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - missing semicolonTIMEOUT
Test same origin redirect: Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - misspeled 'none'TIMEOUT
Test same origin redirect: Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - query values in pathTIMEOUT
Test same origin redirect: Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - report-to presentTIMEOUT
Test same origin redirect: Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - report-uri presentTIMEOUT
Test same origin redirect: Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - unknown policy nameTIMEOUT
Test same origin redirect: Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - unknown policy name in multiple directivesTIMEOUT
Test same origin redirect: Wrong value of `csp` should not trigger sending Sec-Required-CSP Header - url encoded stringTIMEOUT
/content-security-policy/navigate-to/href-location-redirected-blocked.sub.html (2/2, 100.00%, 0.22% of total)TIMEOUT
Test that the child iframe navigation is not allowedNOTRUN
Violation report status OK.FAIL
/content-security-policy/frame-ancestors/frame-ancestors-none-block.html (1/1, 100.00%, 0.11% of total)OK
A 'frame-ancestors' CSP directive with a value 'none' should block rendering.FAIL
/content-security-policy/style-src/inline-style-attribute-allowed.sub.html (1/1, 100.00%, 0.11% of total)OK
Expecting logs: ["PASS"]FAIL
/content-security-policy/style-src/inline-style-allowed-while-cloning-objects.sub.html (1/1, 100.00%, 0.11% of total)OK
Test that violation report event was firedFAIL
/content-security-policy/script-src/script-src-strict_dynamic_in_img-src.html (1/1, 100.00%, 0.11% of total)OK
`strict-dynamic` does not drop whitelists in `img-src`.FAIL
/content-security-policy/style-src-attr-elem/style-src-elem-allowed-src-blocked.html (1/1, 100.00%, 0.11% of total)OK
Inline style should be appliedFAIL
/content-security-policy/style-src/style-blocked.sub.html (1/1, 100.00%, 0.11% of total)OK
Expecting logs: ["violated-directive=style-src","PASS"]FAIL
/content-security-policy/frame-ancestors/frame-ancestors-nested-same-in-same-none-block.html (1/1, 100.00%, 0.11% of total)OK
A 'frame-ancestors' CSP directive with a value 'none' should block rendering in nested frames.FAIL
/content-security-policy/prefetch-src/prefetch-allowed.html (1/3, 33.33%, 0.11% of total)OK
Prefetch succeeds when allowed by prefetch-srcFAIL
/content-security-policy/style-src-attr-elem/style-src-elem-blocked-src-allowed.html (2/2, 100.00%, 0.22% of total)TIMEOUT
Should fire a security policy violation eventNOTRUN
The inline style should not be appliedFAIL
/content-security-policy/script-src/worker-importscripts-blocked.sub.html (1/2, 50.00%, 0.11% of total)OK
worker-importscripts-blockedFAIL
/content-security-policy/frame-ancestors/frame-ancestors-nested-same-in-cross-url-allow.html (1/1, 100.00%, 0.11% of total)TIMEOUT
A 'frame-ancestors' CSP directive with a URL value should block or allow rendering in nested frames as appropriate.NOTRUN
/content-security-policy/plugin-types/plugintypes-mismatched-data.html (1/1, 100.00%, 0.11% of total)TIMEOUT
Should not load the object because its declared type does not match its actual typeNOTRUN
/content-security-policy/connect-src/worker-connect-src-blocked.sub.html (1/1, 100.00%, 0.11% of total)OK
Expecting logs: ["xhr blocked","TEST COMPLETE"]FAIL
/content-security-policy/prefetch-src/prefetch-header-blocked.html (1/3, 33.33%, 0.11% of total)TIMEOUT
Prefetch via `Link` header succeeds when allowed by prefetch-srcTIMEOUT
/content-security-policy/form-action/form-action-src-redirect-blocked.sub.html (1/1, 100.00%, 0.11% of total)OK
Expecting logs: ["violated-directive=form-action","TEST COMPLETE"]FAIL
/content-security-policy/navigate-to/href-location-allowed.html (1/1, 100.00%, 0.11% of total)TIMEOUT
Test that the child iframe navigation is allowedNOTRUN
/content-security-policy/reporting-api/reporting-api-sends-reports-on-violation.https.sub.html (1/3, 33.33%, 0.11% of total)OK
Violation report status OK.FAIL
/content-security-policy/reporting-api/reporting-api-works-on-frame-src.https.sub.html (1/2, 50.00%, 0.11% of total)OK
Violation report status OK.FAIL
/content-security-policy/inside-worker/shared-inheritance.html (3/15, 20.00%, 0.33% of total)TIMEOUT
Cross-origin 'fetch()' in http:TIMEOUT
Cross-origin XHR in http:TIMEOUT
Same-origin => cross-origin 'fetch()' in http:TIMEOUT
/content-security-policy/navigate-to/unsafe-allow-redirects/blocked-end-of-chain.sub.html (1/1, 100.00%, 0.11% of total)OK
Test that the child iframe navigation is blockedFAIL
/content-security-policy/navigate-to/href-location-blocked.sub.html (2/2, 100.00%, 0.22% of total)TIMEOUT
Test that the child iframe navigation is not allowedNOTRUN
Violation report status OK.FAIL
/content-security-policy/media-src/media-src-7_1.html (3/3, 100.00%, 0.33% of total)TIMEOUT
In-policy async video source elementNOTRUN
In-policy async video srcNOTRUN
Should not fire policy violation eventsNOTRUN
/content-security-policy/media-src/media-src-blocked.sub.html (1/5, 20.00%, 0.11% of total)TIMEOUT
Test that securitypolicyviolation events are firedTIMEOUT
/content-security-policy/navigate-to/child-navigates-parent-blocked.sub.html (2/2, 100.00%, 0.22% of total)OK
Test that the child can't navigate the parent because the relevant policy belongs to the navigation initiator (in this case the child which has the policy `navigate-to 'none'`)FAIL
Violation report status OK.FAIL
/content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-sandboxed-cross-url-block.html (1/1, 100.00%, 0.11% of total)TIMEOUT
A 'frame-ancestors' CSP directive with a URL value should compare against each frame's origin rather than URL, so a nested frame with a sandboxed parent frame should be blocked due to the parent having a unique origin.NOTRUN
/content-security-policy/unsafe-hashes/javascript_src_allowed-window_location.html (1/1, 100.00%, 0.11% of total)TIMEOUT
Test that the javascript: src is allowed to runNOTRUN
/content-security-policy/prefetch-src/prefetch-blocked.html (1/3, 33.33%, 0.11% of total)OK
Blocked prefetch generates report.FAIL
/content-security-policy/navigate-to/meta-refresh-cross-origin-blocked.sub.html (2/2, 100.00%, 0.22% of total)OK
Test that the child iframe navigation is not allowedFAIL
Violation report status OK.FAIL
/content-security-policy/frame-ancestors/frame-ancestors-nested-same-in-cross-star-allow.html (1/1, 100.00%, 0.11% of total)TIMEOUT
A 'frame-ancestors' CSP directive with a value '*' should render in nested frames.NOTRUN
/content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-cross-none-block.html (1/1, 100.00%, 0.11% of total)TIMEOUT
A 'frame-ancestors' CSP directive with a value 'none' should block rendering in nested frames.NOTRUN
/content-security-policy/frame-ancestors/frame-ancestors-url-block.html (1/1, 100.00%, 0.11% of total)OK
A 'frame-ancestors' CSP directive with a URL which doesn't match this origin should be blocked.FAIL
/content-security-policy/sandbox/window-reuse-unsandboxed.html (1/1, 100.00%, 0.11% of total)TIMEOUT
Window object should be reusedNOTRUN
/content-security-policy/unsafe-hashes/javascript_src_denied_wrong_hash-window_location.html (1/1, 100.00%, 0.11% of total)TIMEOUT
Test that the javascript: src is not allowed to runNOTRUN
/content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-same-none-block.html (1/1, 100.00%, 0.11% of total)TIMEOUT
A 'frame-ancestors' CSP directive with a value 'none' should block rendering in nested frames.NOTRUN
/content-security-policy/inheritance/window.html (4/4, 100.00%, 0.44% of total)TIMEOUT
`document.write` into `window.open()` inherits policy.FAIL
window.open('blob:...') inherits policy.TIMEOUT
window.open('javascript:...') inherits policy.TIMEOUT
window.open() inherits policy.FAIL
/content-security-policy/frame-ancestors/frame-ancestors-nested-cross-in-cross-star-allow.html (1/1, 100.00%, 0.11% of total)TIMEOUT
A 'frame-ancestors' CSP directive with a value '*' should render in nested frames.NOTRUN