Open Bug 1341817 Opened 8 years ago Updated 8 years ago

Add frame-ancestors CSP directive

Categories

(www.mozilla.org :: Bedrock, defect)

Production
defect
Not set
normal

Tracking

(Not tracked)

People

(Reporter: pmac, Unassigned)

Details

Attachments

(1 file)

Determine exactly which domains are allowed to frame some pages on bedrock and add those to a frame-ancestors directive in our CSP, or remove those framing requirements and set frame-ancestors to 'none'.
Not sure why it attached that PR. It's related though, so okay I guess.
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: