Does Content-Security-Policy ignore X-Frame-Options, returned by a server, or is X-Frame-Options still primary?
Content-Security-Policy
X-Frame-Options
Assuming that I ha
None of your hypotheses are universally true.
frame-ancestors