当前位置:网站首页>关于 Web Content-Security-Policy Directive 通过 meta 元素指定的一些测试用例
关于 Web Content-Security-Policy Directive 通过 meta 元素指定的一些测试用例
2022-07-07 10:07:00 【InfoQ】
frame-src
data:image/s3,"s3://crabby-images/260ea/260eadde2f466303daeec49e2ae43d9f3069041e" alt="null"
data:image/s3,"s3://crabby-images/67d62/67d62108360a704ea3251c6ef9ef50e58607bba5" alt="null"
data:image/s3,"s3://crabby-images/79a71/79a712656cde33624810016f7dd9803c9931add2" alt="null"
测试1:3000 应用(即嵌入 3002 应用的 web 应用里)增加 frame-src
<html>
<head>
<meta http-equiv="Content-Security-Policy" content="frame-src 'self'">
</head>
<h1>Parent</h1>
<iframe src="http://localhost:3002/csp"></iframe>
</html>
data:image/s3,"s3://crabby-images/4dab5/4dab5ddd833652ae04ea80e4f5932c9a12c9dc4b" alt="null"
data:image/s3,"s3://crabby-images/b3730/b3730e05ab70f7723f1086cb23378ad65e3895a2" alt="null"
测试2
data:image/s3,"s3://crabby-images/7bb81/7bb8138c7732dcfe97aac3e0cf867080cb53c843" alt="null"
<html>
<head>
<meta http-equiv="Content-Security-Policy" content="frame-src 'http://localhost:3002'">
</head>
<h1>Parent</h1>
<iframe src="http://localhost:3002/csp"></iframe>
</html>
data:image/s3,"s3://crabby-images/3da91/3da91baa81d01e7a7eb45b930c1b40ae5aca74b0" alt="null"
*
data:image/s3,"s3://crabby-images/bacbc/bacbc85a358c138e74a8b77717bf67d82ba7b0bb" alt="null"
data:image/s3,"s3://crabby-images/0c4fc/0c4fc480a22efb5aca2fe7858bf0eb08b4edb036" alt="null"
data:image/s3,"s3://crabby-images/10848/10848c6940fd38d351ed417d3150835efddd520d" alt="null"
<html>
<head>
<meta http-equiv="Content-Security-Policy" content="frame-src http://localhost:3002/csp">
</head>
<h1>Parent</h1>
<iframe src="http://localhost:3002/csp"></iframe>
</html>
<html>
<head>
<meta http-equiv="Content-Security-Policy" content="frame-src http://localhost:*/csp">
</head>
<h1>Parent</h1>
<iframe src="http://localhost:3002/csp"></iframe>
</html>
data:image/s3,"s3://crabby-images/9f775/9f775bbfdf1cd38debc79b1eba9a3e870aa95828" alt="null"
data:image/s3,"s3://crabby-images/24fe0/24fe093a6e09c58af24878ab4d71bfcbd4e1b976" alt="null"
data:image/s3,"s3://crabby-images/62246/622464f6296f7825880a7a3b1322b435228adb44" alt="null"
边栏推荐
- Poor math students who once dropped out of school won the fields award this year
- 【紋理特征提取】基於matlab局部二值模式LBP圖像紋理特征提取【含Matlab源碼 1931期】
- Various uses of vim are very practical. I learned and summarized them in my work
- Flet教程之 17 Card卡片组件 基础入门(教程含源码)
- Talk about SOC startup (x) kernel startup pilot knowledge
- SwiftUI 教程之如何在 2 秒内实现自动滚动功能
- Half of the people don't know the difference between for and foreach???
- UP Meta—Web3.0世界创新型元宇宙金融协议
- Zero shot, one shot and few shot
- MATLAB实现Huffman编码译码含GUI界面
猜你喜欢
Complete collection of common error handling in MySQL installation
SwiftUI Swift 内功之如何在 Swift 中进行自动三角函数计算
Rationaldmis2022 advanced programming macro program
111.网络安全渗透测试—[权限提升篇9]—[Windows 2008 R2内核溢出提权]
[filter tracking] strapdown inertial navigation pure inertial navigation solution matlab implementation
相机标定(2): 单目相机标定总结
【最短路】Acwing1128信使:floyd最短路
18 basic introduction to divider separator component of fleet tutorial (tutorial includes source code)
Summed up 200 Classic machine learning interview questions (with reference answers)
Poor math students who once dropped out of school won the fields award this year
随机推荐
Flet教程之 19 VerticalDivider 分隔符组件 基础入门(教程含源码)
Various uses of vim are very practical. I learned and summarized them in my work
Fleet tutorial 19 introduction to verticaldivider separator component Foundation (tutorial includes source code)
Problem: the string and characters are typed successively, and the results conflict
The road to success in R & D efficiency of 1000 person Internet companies
请查收.NET MAUI 的最新学习资源
总结了200道经典的机器学习面试题(附参考答案)
【神经网络】卷积神经网络CNN【含Matlab源码 1932期】
Suggestions on one-stop development of testing life
zero-shot, one-shot和few-shot
Talk about SOC startup (VII) uboot startup process III
[full stack plan - programming language C] basic introductory knowledge
Fleet tutorial 14 basic introduction to listtile (tutorial includes source code)
Mise en œuvre du codage Huffman et du décodage avec interface graphique par MATLAB
MATLAB實現Huffman編碼譯碼含GUI界面
[shortest circuit] acwing 1127 Sweet butter (heap optimized dijsktra or SPFA)
2022年在启牛开华泰的账户安全吗?
Sonar:Cognitive Complexity认知复杂度
Have you ever met flick Oracle CDC, read a table without update operation, and read it repeatedly every ten seconds
STM32F1与STM32CubeIDE编程实例-MAX7219驱动8位7段数码管(基于SPI)