It's reasonable to give sites the ability to enforce restrictions on framed content. w3c.github.io/webappsec-csp/… will be a safe way of doing so.
1
7
7
It boils down to an `<iframe sandbox>` variant that requires both sides to opt-in. I think it has lots of potential.
1
2
Replying to @mikewest
@mikewest Get it on YouTube and in Chrome and I'll use it.

Nov 30, 2015 · 3:35 PM UTC

1