Allow embedded credentials for relative URLs.

If a user visits `http://user:pass@example.com/`, we should allow
`<img src='/whatever.png'>`. Currently, we're doing the embedded
credential check on the completed URL, which ends up blocking the
request.

Bug: 731618
Change-Id: I5a15187a2a0fd39822467d64efeedaae637765a8
Reviewed-on: https://chromium-review.googlesource.com/530308
Reviewed-by: Jochen Eisinger <jochen@chromium.org>
Commit-Queue: Mike West <mkwst@chromium.org>
Cr-Commit-Position: refs/heads/master@{#479147}
12 files changed