Feature request —let scoped frame-src in csp_overrides, or a native video-playback host API

Please I need somebody to give me something. I have posted this request over three times now and I haven’t gotten a response from anybody.

I’m building a YouTube research assistant as an Anna App. A core part of the experience is playing cited video moments directly inside the app window — users jump to specific timestamps Bob references, without leaving the conversation.

Currently, ui.csp_overrides accepts connect-src, img-src, media-src, font-src, style-src, and script-src, but not frame-src — meaning no App can embed a YouTube (or any) player iframe, even from an explicitly-declared, developer-controlled origin.

Request: allow frame-src in csp_overrides, scoped the same way external_origins already scopes connect-src/img-src — an explicit allowlist of origins, not an open directive. This wouldn’t broadly relax security; it would extend the same “developer declares specific trusted origins” pattern you already use elsewhere to one more directive.

Alternatively, a native host-mediated video-playback component (similar in spirit to image.generate/image.edit) would solve this without touching CSP at all.

Without one of these, any App built around embedded media playback — not just mine — has no path to working in-window.playback—not

Hi @Ilaye :waving_hand:

First off — we’re really sorry for the late response. :folded_hands: You’ve raised this more than once, and you absolutely deserved a reply sooner. Thank you for your patience and for taking the time to write it up so clearly each time.

Good news: we’ve received this request, along with your earlier posts on the same topic. :white_check_mark: The use case makes total sense — in-window playback of cited video moments is exactly the kind of experience we want Anna Apps to enable, and your write-up of the two possible paths (scoped frame-src in csp_overrides vs. a host-mediated playback API) is genuinely helpful input.

Our team is actively working on how best to support this. :hammer_and_wrench: Since it touches the App sandbox security model, we want to get it right rather than rush it — but it’s on our radar and moving.

We’ll post an update right here in this thread once there’s something concrete to share. :open_mailbox_with_raised_flag:

Thanks again for building on Anna and for pushing us to make the platform better — feedback like yours is exactly what shapes it. :yellow_heart:

Hi @Ilaye :waving_hand:

First — a sincere apology for how long it took to get a proper response to this. You’ve raised it multiple times, and you deserved an answer sooner. Thank you for your patience and for the exceptionally clear write-up. :folded_hands:

Good news: this is done, and it ships today (Friday)! :tada:

What’s changing

:white_check_mark: frame-src is now supported in ui.csp_overrides — exactly the way you proposed: an explicit allowlist of https:// origins, scoped the same way external_origins already works (no wildcards, no open directive, up to 8 origins).

"ui": {
  "csp_overrides": {
    "frame-src": ["https://www.youtube-nocookie.com"]
  }
}

And a bit more you didn’t ask for (but would have hit next) :grinning_face_with_smiling_eyes:

While implementing this, we found two more walls behind the CSP one, and fixed both:

:clapper_board: Permissions-Policy delegation — declaring frame-src now automatically delegates autoplay, encrypted-media, fullscreen, and picture-in-picture to your declared origins, through the whole chain. Without this, the player would render but fullscreen and autoplay-after-timestamp-jump (your core use case!) would silently fail. One thing you still do on your side: add the allow attribute to your own embed iframe:

<iframe
  src="https://www.youtube-nocookie.com/embed/VIDEO_ID?start=42"
  allow="autoplay; encrypted-media; fullscreen; picture-in-picture">
</iframe>

:link: Referrer-Policy — YouTube embeds require a Referer to validate the embedding origin. Apps that declare frame-src now get strict-origin-when-cross-origin on bundle assets (origin only, no paths leaked). Tip: don’t add referrerpolicy="no-referrer" to your embed iframe, or the player will fail with error 153.

How to get it

  • :rocket: Platform update rolls out today
  • :package: Then update the CLI: @anna-ai/cli@0.1.56
  • :books: Docs: the app-ui-manifest page has a new “Embedding third-party content (frame-src)” section
  • :puzzle_piece: Working example: anna-app-frame-embed-demo in the examples repo — a minimal app embedding a video player with timestamp-jump buttons (your exact scenario)

:warning: One parity note: the local harness does not simulate CSP or Permissions-Policy headers, so an embed that works locally isn’t proof it will work in production. Please rely on anna-app validate and a working draft on the platform for final verification.

On the native video-playback host API

We considered it, but decided against it (for now): YouTube’s ToS requires the official iframe player anyway, so a host-mediated component would face the same embedding constraints — just moved to our page instead of yours — while locking the solution to video. Scoped frame-src solves the general case: maps, players, document previews, any explicitly-declared third-party embed. :world_map::video_camera::page_facing_up:

Really looking forward to seeing the YouTube research assistant in the store — jumping to cited timestamps in-window sounds genuinely delightful. If anything doesn’t behave as described once this lands, post here and we’ll jump on it fast. :blue_heart:

Thank you so much. I sincerely appreciate the effort.