WPT
wpt / content-security-policy / embedded-enforcement / allow_csp_from-header.html
Spec: Content Security Policy: Embedded Enforcement ↗
Runs: Chrome 155.0.8041.0 (wpt@2c385f65e, 2026-09-04) | Firefox 157.0a1 (wpt@2c385f65e, 2026-09-04) | Safari 251 preview (wpt@5ce815a83, 2026-08-27) | Ladybird 1.0-a7825 (wpt@2c385f65e, 2026-09-04) | Servo Servo 0.6 (wpt@7e3d005d7, 2026-09-03) | Blitz a50cb8971 (wpt@a95401e4e, 2026-09-03)
View on the Blitz WPT dashboard | Open test on wpt.live | wpt.fyi
| Chrome | Firefox | Safari | Ladybird | Servo | Blitz | |
|---|---|---|---|---|---|---|
| Total | 12/12 | 4/12 | 4/12 | 4/12 | 4/12 | NOT RUN |
| Subtest | Chrome | Firefox | Safari | Ladybird | Servo | Blitz |
|---|---|---|---|---|---|---|
| Same origin iframes with correct Allow-CSP-From header are allowed. | PASS | PASS | PASS | PASS | PASS | — |
| Same origin iframes with an empty Allow-CSP-From header get blocked. | PASS | FAIL | FAIL | FAIL | FAIL | — |
| Same origin iframes without Allow-CSP-From header gets blocked. | PASS | FAIL | FAIL | FAIL | FAIL | — |
| Same origin iframes are blocked if Allow-CSP-From does not match origin. | PASS | FAIL | FAIL | FAIL | FAIL | — |
| Cross origin iframe with an empty Allow-CSP-From header gets blocked. | PASS | FAIL | FAIL | FAIL | FAIL | — |
| Cross origin iframe without Allow-CSP-From header gets blocked. | PASS | FAIL | FAIL | FAIL | FAIL | — |
| Cross origin iframe with correct Allow-CSP-From header is allowed. | PASS | PASS | PASS | PASS | PASS | — |
| Iframe with improper Allow-CSP-From header gets blocked. | PASS | FAIL | FAIL | FAIL | FAIL | — |
| Allow-CSP-From header with a star value allows cross origin frame. | PASS | PASS | PASS | PASS | PASS | — |
| Star Allow-CSP-From header enforces EmbeddingCSP. | PASS | TIMEOUT | TIMEOUT | TIMEOUT | TIMEOUT | — |
| Allow-CSP-From header enforces EmbeddingCSP. | PASS | TIMEOUT | TIMEOUT | TIMEOUT | TIMEOUT | — |
| 'self' in blanket enforced EmbeddingCSP matches the target response origin. | PASS | PASS | PASS | PASS | PASS | — |