IFrames blocked by CSP should generate a 'load', not 'error' event, regardless of blocked state. This means they appear to be normal cross-origin loads, thereby not leaking URL information directly to JS.

Summary

Harness status: OK

Found 3 tests

Details

ResultTest NameMessage
Passframe-src-cross-origin-load
Asserts runNo asserts ran
Passframe-src-cross-origin-load 1
Asserts runNo asserts ran
Passframe-src-cross-origin-load 2
Asserts runNo asserts ran