Forum Moderators: martinibuster
Refused to frame '' because it violates the following Content Security Policy directive: "frame-src cm.g.doubleclick.net googleads.g.doubleclick.net accounts.google.com pagead2.googlesyndication.com/pagead/s/cookie_push.html gmsg: ". Are you using, or could you (at some point in the future) be using i-frames from sources other that Adsense? I really don't see any logic for using a CSP to restrict the sources of frames on your site, with the one exception case, that user's are able to add i-frames without your knowledge.
Header add Content-Security-Policy "frame-src 'self';" would prevent external content from being displayed. If you have changed that, what headers are being set now? Content-Security-Policy: frame-src <source> <source>; is what you are aiming for?
*.googleadservices.com *.googletagmanager.com *.googletagservices.com *.googlesyndication.com *.google-analytics.com *.googleapis.com *.ggpht.com *.google.com *.google.co.uk *.gstatic.com *.doubleclick.net