forked from mirrors/gecko-dev
# ignore-this-changeset Differential Revision: https://phabricator.services.mozilla.com/D35928 --HG-- extra : source : 4e926f91b17c2b13cdaf13e017629286275dbc00
11 lines
298 B
JavaScript
11 lines
298 B
JavaScript
/* import-globals-from mixedContentTest.js */
|
|
"use strict";
|
|
|
|
document.open();
|
|
// eslint-disable-next-line no-unsanitized/method
|
|
document.write("This is insecure XSS script " + document.cookie);
|
|
isSecurityState(
|
|
"broken",
|
|
"security broken after document write from unsecure script"
|
|
);
|
|
finish();
|