chromium/third_party/blink/web_tests/http/tests/security/mixedContent/insecure-formSubmission-in-main-frame-allowed.html

<html>
<body>
<script>
if (window.testRunner) {
    testRunner.waitUntilDone();
    testRunner.dumpAsText();
    testRunner.setPopupBlockingEnabled(false);
}

window.addEventListener("message", function (e) {
  if (window.testRunner)
    testRunner.notifyDone();
}, false);

</script>
<p>This test opens a window that shows a form with "action" pointing to insecure
location. We should trigger a mixed content callback even though we've set the preference to block this, because we've overriden the preferences via a web permission client callback.</p>
<script>
window.open("https://127.0.0.1:8443/security/mixedContent/resources/frame-with-insecure-formSubmission.html");
</script>
</body>
</html>