Comment to How to re-enable iFrames on 14.0.0-RC2?
This is misleading, the matter of Content-Security-Policy: frame-ancestors' header value
regards who is allowed to embed content from your site onto their site. Which is limited to "self."