What determines how the frame-ancestors value is set in the Content-Security-Policy?
I’m trying to frame content from a 3rd-party provider in an iframe on my Wordpress site. I’m emulating something that’s set up on an affiliated site. When loading and attempting to download the iframe content, an error is logged: ancestor violates the following Content Security Policy directive: "frame-ancestors 'none'".