CSP frame-ancestors Restricts Page Embedding
CSP frame-ancestors Restricts Page Embedding Clickjacking does not require an attacker to replace the target application’s interface. A hostile page can place the real application inside a transparent or carefully positioned frame, then arrange decoy controls so a user’s click lands on an authenticated action in the framed page. The frame-ancestors directive in Content Security Policy moves the embedding decision to the response being framed. The target declares which ancestors are acceptable. A conforming browser checks the ancestor chain before allowing the protected resource to load in a nested browsing context.