Consider a console warning if XFO is overridden by frame-ancestors |
|||
Issue descriptionPer https://www.w3.org/TR/CSP2/#frame-ancestors-and-frame-options, when frame-ancestors is present, X-Frame-Options should be ignored. This is anecdotally surprising to some developers, so we could consider printing a console warning when it happens.
,
Mar 2 2017
One reason this is likely surprising to developers is that IE, Edge, Safari, and Firefox don't work like this. Test page: http://www.enhanceie.com/test/clickjack/CSPTrumpsXFO.asp
,
Nov 10 2017
,
Feb 18 2018
|
|||
►
Sign in to add a comment |
|||
Comment 1 by mkwst@chromium.org
, Mar 2 2017