CONSOLE ERROR: Refused to display 'http://localhost:8080/security/contentSecurityPolicy/resources/frame-ancestors.pl?policy=http://localhost:8080' in a frame because an ancestor violates the following Content Security Policy directive: "frame-ancestors http://localhost:8080". A 'frame-ancestors' CSP directive with a URL value should block or allow rendering in nested frames as appropriate. On success, you will see a series of "PASS" messages, followed by "TEST COMPLETE". PASS The inner IFrame passed. PASS successfullyParsed is true TEST COMPLETE -------- Frame: '-->' -------- Testing a cross-origin child with a policy of "http://localhost:8080" nested in a cross-origin parent. On success, you will see a series of "PASS" messages, followed by "TEST COMPLETE". IFrame load event fired: the IFrame is cross-origin (or was blocked). PASS The IFrame should have been blocked (or cross-origin). It was. -------- Frame: '/-->' --------