CSP is super fun.
"In Chrome and Safari, omitting frame-ancestors allows framing by a file:// or data: URI, but specifying frame-ancestors "*" does not."
github.com/w3c/webappsec-csp…
Feb 24, 2020 · 5:51 PM UTC
2
Feb 24, 2020 · 5:51 PM UTC