Click here to download the Blitz Browser!

WPT

wpt / content-security-policy / embedded-enforcement / allow_csp_from-header.html

Spec: Content Security Policy: Embedded Enforcement ↗

Runs: Chrome 155.0.8041.0 (wpt@2c385f65e, 2026-09-04) | Firefox 157.0a1 (wpt@2c385f65e, 2026-09-04) | Safari 251 preview (wpt@5ce815a83, 2026-08-27) | Ladybird 1.0-a7825 (wpt@2c385f65e, 2026-09-04) | Servo Servo 0.6 (wpt@7e3d005d7, 2026-09-03) | Blitz a50cb8971 (wpt@a95401e4e, 2026-09-03)

View on the Blitz WPT dashboard | Open test on wpt.live | wpt.fyi

ChromeFirefoxSafariLadybirdServoBlitz
Total12/124/124/124/124/12NOT RUN
SubtestChromeFirefoxSafariLadybirdServoBlitz
Same origin iframes with correct Allow-CSP-From header are allowed.PASSPASSPASSPASSPASS
Same origin iframes with an empty Allow-CSP-From header get blocked.PASSFAILFAILFAILFAIL
Same origin iframes without Allow-CSP-From header gets blocked.PASSFAILFAILFAILFAIL
Same origin iframes are blocked if Allow-CSP-From does not match origin.PASSFAILFAILFAILFAIL
Cross origin iframe with an empty Allow-CSP-From header gets blocked.PASSFAILFAILFAILFAIL
Cross origin iframe without Allow-CSP-From header gets blocked.PASSFAILFAILFAILFAIL
Cross origin iframe with correct Allow-CSP-From header is allowed.PASSPASSPASSPASSPASS
Iframe with improper Allow-CSP-From header gets blocked.PASSFAILFAILFAILFAIL
Allow-CSP-From header with a star value allows cross origin frame.PASSPASSPASSPASSPASS
Star Allow-CSP-From header enforces EmbeddingCSP.PASSTIMEOUTTIMEOUTTIMEOUTTIMEOUT
Allow-CSP-From header enforces EmbeddingCSP.PASSTIMEOUTTIMEOUTTIMEOUTTIMEOUT
'self' in blanket enforced EmbeddingCSP matches the target response origin.PASSPASSPASSPASSPASS