WPT
wpt / content-security-policy / navigation / to-javascript-parent-initiated-check-csp-order.html
Spec: Content Security Policy ↗
Runs: Chrome 155.0.8041.0 (wpt@18be93235, 2026-09-04) | Firefox 157.0a1 (wpt@18be93235, 2026-09-04) | Safari 251 preview (wpt@2c385f65e, 2026-09-04) | Ladybird 1.0-70fb3 (wpt@0c9001c53, 2026-09-04) | Servo Servo 0.6 (wpt@2c385f65e, 2026-09-04) | Blitz a50cb8971 (wpt@a95401e4e, 2026-09-03)
View on the Blitz WPT dashboard | Open test on wpt.live | wpt.fyi
| Chrome | Firefox | Safari | Ladybird | Servo | Blitz | |
|---|---|---|---|---|---|---|
| Total | 7/7 | 7/7 | 7/7 | 0/7 | 7/7 | NOT RUN |
| Subtest | Chrome | Firefox | Safari | Ladybird | Servo | Blitz |
|---|---|---|---|---|---|---|
| Executing the javascript URL should violate the parent's CSP for iframe.contentWindow.location.href | PASS | PASS | PASS | FAIL | PASS | — |
| Executing the javascript URL should violate the parent's CSP for iframe.src | PASS | PASS | PASS | FAIL | PASS | — |
| Executing the javascript URL should violate the parent's CSP for a[target=iframeWithScriptSrcNone].href | PASS | PASS | PASS | FAIL | PASS | — |
| Executing the javascript URL should violate the parent's CSP for a[target=otherTabWithScriptSrcNone].href | PASS | PASS | PASS | FAIL | PASS | — |
| Executing the javascript URL should violate the parent's CSP for area[target=iframeWithScriptScrcNone].href | PASS | PASS | PASS | FAIL | PASS | — |
| Executing the javascript URL should violate the parent's CSP for area[target=otherTabWithScriptSrcNone].href | PASS | PASS | PASS | FAIL | PASS | — |
| Executing the javascript URL should violate the parent's CSP for otherTabWithScriptSrcNone.location.href | PASS | PASS | PASS | FAIL | PASS | — |