I’m building a YouTube research assistant as an Anna App. A core part of the experience is playing cited video moments directly inside the app window — users jump to specific timestamps Bob references, without leaving the conversation.
Currently, ui.csp_overrides accepts connect-src, img-src, media-src, font-src, style-src, and script-src, but not frame-src — meaning no App can embed a YouTube (or any) player iframe, even from an explicitly-declared, developer-controlled origin.
Request: allow frame-src in csp_overrides, scoped the same way external_origins already scopes connect-src/img-src — an explicit allowlist of origins, not an open directive. This wouldn’t broadly relax security; it would extend the same “developer declares specific trusted origins” pattern you already use elsewhere to one more directive.
Alternatively, a native host-mediated video-playback component (similar in spirit to image.generate/image.edit) would solve this without touching CSP at all.
Without one of these, any App built around embedded media playback — not just mine — has no path to working in-window.
Closing the loop on this thread too — thank you again for raising it (more than once!), and apologies that this earlier post went unanswered for so long.
Good news: this is fixed and already live.
Scoped frame-src is now supported in ui.csp_overrides, exactly as you proposed — an explicit allowlist of https:// origins, scoped the same way external_origins works (no wildcards, up to 8 origins):
Along the way we also fixed two more things you would have hit next:
Permissions-Policy delegation — declaring frame-src now automatically delegates autoplay, encrypted-media, fullscreen, and picture-in-picture to your declared origins. Just remember to add allow="autoplay; encrypted-media; fullscreen; picture-in-picture" to your own embed <iframe>.
Referrer-Policy — YouTube embeds need a Referer to validate the embedding origin; apps that declare frame-src now get strict-origin-when-cross-origin on bundle assets. (Tip: don’t set referrerpolicy="no-referrer" on the embed, or you’ll see error 153.)
Versions
Platform: 1.1.0-beta.180 (live since Sep 25)
CLI: @anna-ai/cli@0.1.56 or later — run npm i -g @anna-ai/cli@latest
Working example: anna-app-frame-embed-demo in the examples repo — a minimal app embedding a player with timestamp-jump buttons, i.e. your exact scenario
Full details and the discussion are over in #343, so I’ll mark this one as resolved. Can’t wait to see the YouTube research assistant in the store — if anything doesn’t behave as described, just ping us and we’ll jump on it.