frame-ancestors

Default Attribute

self

Policy Description

The HTTP Content-Security-Policy (CSP) frame-ancestors directive specifies valid parents that may embed a page usingĀ <frame>,Ā <iframe>,Ā <object>,Ā <embed>, orĀ <applet>.Setting this directive to ā€˜noneā€™ is similar toĀ X-Frame-Options: deny (which is also supported in older browsers).