← Back to release summary

CSP: Embedded Enforcement

Category
Security
Type
New or changed feature
Status
Enabled by default (Chrome 61)
Intent stage
None

Summary

CSP's Embedded enforcement defines a mechanism by which a web page can embed a nested browsing context if and only if it agrees to enforce a particular set of restrictions upon itself. We should prototype an implementation to see if it's something that solves real problems in a way we can ship.

Standards & signals

View on chromestatus.com