Feature request — allow scoped frame-src in csp_overrides, or a native video-playback host API

I’m building a YouTube research assistant as an Anna App. A core part of the experience is playing cited video moments directly inside the app window — users jump to specific timestamps Bob references, without leaving the conversation.

Currently, ui.csp_overrides accepts connect-src, img-src, media-src, font-src, style-src, and script-src, but not frame-src — meaning no App can embed a YouTube (or any) player iframe, even from an explicitly-declared, developer-controlled origin.

Request: allow frame-src in csp_overrides, scoped the same way external_origins already scopes connect-src/img-src — an explicit allowlist of origins, not an open directive. This wouldn’t broadly relax security; it would extend the same “developer declares specific trusted origins” pattern you already use elsewhere to one more directive.

Alternatively, a native host-mediated video-playback component (similar in spirit to image.generate/image.edit) would solve this without touching CSP at all.

Without one of these, any App built around embedded media playback — not just mine — has no path to working in-window.

Hi @Ilaye :waving_hand:

Closing the loop on this thread too — thank you again for raising it (more than once!), and apologies that this earlier post went unanswered for so long. :folded_hands:

Good news: this is fixed and already live. :white_check_mark:

Scoped frame-src is now supported in ui.csp_overrides, exactly as you proposed — an explicit allowlist of https:// origins, scoped the same way external_origins works (no wildcards, up to 8 origins):

"ui": {
  "csp_overrides": {
    "frame-src": ["https://www.youtube-nocookie.com"]
  }
}

Along the way we also fixed two more things you would have hit next:

  • :clapper_board: Permissions-Policy delegation — declaring frame-src now automatically delegates autoplay, encrypted-media, fullscreen, and picture-in-picture to your declared origins. Just remember to add allow="autoplay; encrypted-media; fullscreen; picture-in-picture" to your own embed <iframe>.
  • :link: Referrer-Policy — YouTube embeds need a Referer to validate the embedding origin; apps that declare frame-src now get strict-origin-when-cross-origin on bundle assets. (Tip: don’t set referrerpolicy="no-referrer" on the embed, or you’ll see error 153.)

Versions :package:

  • Platform: 1.1.0-beta.180 (live since Sep 25)
  • CLI: @anna-ai/cli@0.1.56 or later — run npm i -g @anna-ai/cli@latest

Resources :books:

  • Docs: App UI Manifest → “Embedding third-party content (frame-src)”
  • Working example: anna-app-frame-embed-demo in the examples repo — a minimal app embedding a player with timestamp-jump buttons, i.e. your exact scenario :blush:

Full details and the discussion are over in #343, so I’ll mark this one as resolved. Can’t wait to see the YouTube research assistant in the store — if anything doesn’t behave as described, just ping us and we’ll jump on it. :rocket:

Happy building! :yellow_heart: