CSP frame-src
What your page may put in a frame.
- Falls back to
child-src, then default-src- Group
- Fetch directives
Detail
Controls what you embed โ the opposite direction from frame-ancestors, which controls who may embed you. Confusing the two is the most common CSP mistake after unsafe-inline. Payment providers, video embeds and auth widgets all need entries here.
Example
frame-src https://js.stripe.com https://www.youtube-nocookie.com