This is misleading, the matter of Content-Security-Policy: frame-ancestors' header value
regards who is allowed to embed content from your site onto their site. Which is limited to "self."