The HTTP Content-Security-Policy (CSP) frame-src directive specifies valid sources for nested browsing contexts loading using elements such as <frame> and <iframe>.
Note: frame-src allows you to specify where iframes in a page may be loaded from. This differs from frame-ancestors, which allows you to specify what parent source may embed a page.
| CSP version | 1 |
|---|---|
| Directive type | Fetch directive |
| Fallback | If this directive is absent, the user agent will look for the child-src directive (which falls back to the default-src directive). |