Default Attribute
self
Policy Description
The HTTP Content-Security-Policy (CSP) frame-ancestors directive specifies valid parents that may embed a page usingĀ <frame>
,Ā <iframe>
,Ā <object>
,Ā <embed>
, orĀ <applet>
.Setting this directive to ānoneā is similar toĀ X-Frame-Options: deny (which is also supported in older browsers).