Skip to content

Chrome seems to avoid overloading frame-ancestors #16

@colorvamp

Description

@colorvamp

If the target page has:
Content-Security-Policy: frame-ancestors 'none';
Chrome-csp-disable is unable to disable csp, I have done some tests, its ok on Firefox, but dont work on any webkit based browser, tested in Opera, Chromium and Chrome.

I have prepared my own domain for this test: https://jsfiddle.net/sombra2eternity/dtfL80am/
You will be unable to load this iframe on Chrome. I havent found any documentation describing this behaviour though :/

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions