The origin of an URL is called "unique" when it is considered to be different from every origin, including itself. The origin of a data-url is unique. When the current origin is unique, the CSP source 'self' must not match any URL.

Summary

Harness status: OK

Found 1 tests

Details

ResultTest NameMessage
PassIframe's url must not match with 'self'. It must be blocked.
Asserts runNo asserts ran