4 <meta http-equiv=
"Content-Security-Policy" content=
"suborigin foobar">
5 <title>The
<meta
> tag does not allow a page to enter a suborigin.
</title>
6 <script src=
"/resources/testharness.js"></script>
7 <script src=
"/resources/testharnessreport.js"></script>
10 window
.onmessage = function(event
) {
13 secret
= document
.getElementById('iframe').contentWindow
.secret
;
17 assert_equals(secret
, 'SecurityError: Blocked a frame with origin \"http://127.0.0.1:8000\" from accessing a cross-origin frame.');
21 <iframe id=
"iframe" src=
"resources/post-to-parent.php?suborigin=foobar"></iframe>