View source | Clear CSP | Set default-src 'self' | Set frame-ancestors 'self'


Test 1: Framing self:
Test 2: Framing cross-origin:
Test 3: JS retrieving data from another domain: (JS did not run... Were inline scripts blocked?)