WICG / csp-next

A Modest Content Security Proposal
https://wicg.github.io/csp-next/scripting-policy.html
Other
39 stars 3 forks source link

What about frame ancestors? #6

Open empijei opened 4 years ago

empijei commented 4 years ago

CSP is often used as a more refined and secure form of X-Frame-Options.

As far as I understand from your proposal you plan to limit what the document with Confinement Policy can frame, but not what it can be framed by.

Did I read it right? Do you have something in mind to carry over this feature?