Embed CSP test page (DEMO). Pretend third-party site. Developer docs · frames blocked · script blocked · allowed

Frames blocked (frame-src 'none')

This page is served with the header:
Content-Security-Policy: default-src 'self'; script-src 'self'; style-src 'self'; frame-src 'none'; base-uri 'none'
Expected: our script runs, the iframe is blocked, so you see a styled “Request service” button that opens the form in a new tab, and a console warning names the CSP lines to add.