CSP is super fun. "In Chrome and Safari, omitting frame-ancestors allows framing by a file:// or data: URI, but specifying frame-ancestors "*" does not." github.com/w3c/webappsec-csp…

Feb 24, 2020 · 5:51 PM UTC

2