docs.rodeo

MDN Web Docs mirror

Content-Security-Policy: fenced-frame-src directive

{{SeeCompatTable}} 

The HTTP {{HTTPHeader("Content-Security-Policy")}}  (CSP) fenced-frame-src directive specifies valid sources for nested browsing contexts loaded into {{HTMLElement("fencedframe")}}  elements.

CSP version 1
Directive type `{{Glossary("Fetch directive")}}` 
Fallback If this directive is absent, the user agent will look for the `{{CSP("frame-src")}}`  directive (which falls back to the `{{CSP("child-src")}}`  directive).

Syntax

Content-Security-Policy: fenced-frame-src <source-expression-list>;

Examples

Violation cases

Given this CSP header:

Content-Security-Policy: fenced-frame-src https://example.com/

The following sources will not load in a fenced frame:

Specifications

{{Specifications}} 

Browser compatibility

{{Compat}} 

See also

In this article

View on MDN