Policy clarification: embedding user-selected websites in an extension page
Would Mozilla consider an exception to the security-header policy for an extension that embeds user-selected websites within its own locally packaged page?
The proposed behavior would remove X-Frame-Options and CSP frame-ancestors restrictions only for those embedded pages. Ordinary browsing and other CSP directives would remain unaffected.
Vivaldi’s persistent Web Panels provide a similar user experience, while Chrome’s declarativeNetRequest API provides the technical capability to modify framing headers. I understand these implementations differ, but I’d like to know whether Firefox offers an approved path to comparable functionality.
Would explicit user consent and per-site controls make this eligible for an exception? If not, is there a supported alternative or a way to request a private, pre-submission review?
All Replies (1)
You might wanna ask around in discourse.mozilla.org/c/add-ons/35