@@ -149,15 +149,15 @@ def request_for user_agent, request_uri=nil, options={:ssl => false}
149149
150150 it "does not filter any directives for Chrome" do
151151 policy = ContentSecurityPolicy . new ( complex_opts , :request => request_for ( CHROME ) )
152- expect ( policy . value ) . to eq ( "default-src 'self'; base-url 'self'; block-all-mixed-content ; child-src 'self'; connect-src 'self'; font-src 'self'; form-action 'self'; frame-ancestors 'self'; frame-src 'self'; img-src 'self' data:; media-src 'self'; object-src 'self'; plugin-types 'self'; sandbox 'self'; script-src 'self'; style-src 'self'; report-uri 'self';" )
152+ expect ( policy . value ) . to eq ( "default-src 'self'; base-uri 'self'; block-all-mixed-content ; child-src 'self'; connect-src 'self'; font-src 'self'; form-action 'self'; frame-ancestors 'self'; frame-src 'self'; img-src 'self' data:; media-src 'self'; object-src 'self'; plugin-types 'self'; sandbox 'self'; script-src 'self'; style-src 'self'; report-uri 'self';" )
153153 end
154154
155155 it "filters blocked-all-mixed-content, child-src, and plugin-types for firefox" do
156156 policy = ContentSecurityPolicy . new ( complex_opts , :request => request_for ( FIREFOX ) )
157- expect ( policy . value ) . to eq ( "default-src 'self'; base-url 'self'; connect-src 'self'; font-src 'self'; form-action 'self'; frame-ancestors 'self'; frame-src 'self'; img-src 'self' data:; media-src 'self'; object-src 'self'; sandbox 'self'; script-src 'self'; style-src 'self'; report-uri 'self';" )
157+ expect ( policy . value ) . to eq ( "default-src 'self'; base-uri 'self'; connect-src 'self'; font-src 'self'; form-action 'self'; frame-ancestors 'self'; frame-src 'self'; img-src 'self' data:; media-src 'self'; object-src 'self'; sandbox 'self'; script-src 'self'; style-src 'self'; report-uri 'self';" )
158158 end
159159
160- it "filters base-url , blocked-all-mixed-content, child-src, form-action, frame-ancestors, and plugin-types for safari" do
160+ it "filters base-uri , blocked-all-mixed-content, child-src, form-action, frame-ancestors, and plugin-types for safari" do
161161 policy = ContentSecurityPolicy . new ( complex_opts , :request => request_for ( SAFARI ) )
162162 expect ( policy . value ) . to eq ( "default-src 'self'; connect-src 'self'; font-src 'self'; frame-src 'self'; img-src 'self' data:; media-src 'self'; object-src 'self'; sandbox 'self'; script-src 'self'; style-src 'self'; report-uri 'self';" )
163163 end
0 commit comments