# Feature request —let scoped frame-src in csp\_overrides, or a native video-playback host API

**URL:** <https://forum.anna.partners/t/feature-request-let-scoped-frame-src-in-csp-overrides-or-a-native-video-playback-host-api/343>\
**Category:** Developers\
**Created:** [September 24, 2026, 1:33pm UTC](https://forum.anna.partners/t/feature-request-let-scoped-frame-src-in-csp-overrides-or-a-native-video-playback-host-api/343 "2026-09-24T13:33:04Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ilaye](https://avatars.discourse-cdn.com/v4/letter/i/e480ec/32.png) [@Ilaye](https://forum.anna.partners/u/Ilaye)\
**Post date:** [September 24, 2026, 1:33pm UTC](https://forum.anna.partners/t/feature-request-let-scoped-frame-src-in-csp-overrides-or-a-native-video-playback-host-api/343/1 "2026-09-24T13:33:04Z")

</div>

Please I need somebody to give me something. I have posted this request over three times now and I haven’t gotten a response from anybody.

I’m building a YouTube research assistant as an Anna App. A core part of the experience is playing cited video moments directly inside the app window — users jump to specific timestamps Bob references, without leaving the conversation.

Currently, ui.csp\_overrides accepts connect-src, img-src, media-src, font-src, style-src, and script-src, but not frame-src — meaning no App can embed a YouTube (or any) player iframe, even from an explicitly-declared, developer-controlled origin.

Request: allow frame-src in csp\_overrides, scoped the same way external\_origins already scopes connect-src/img-src — an explicit allowlist of origins, not an open directive. This wouldn’t broadly relax security; it would extend the same “developer declares specific trusted origins” pattern you already use elsewhere to one more directive.

Alternatively, a native host-mediated video-playback component (similar in spirit to image.generate/image.edit) would solve this without touching CSP at all.

Without one of these, any App built around embedded media playback — not just mine — has no path to working in-window.playback—not

---

<div class="post-metadata">

**Author:** ![hunter](https://yyz1.discourse-cdn.com/flex033/user_avatar/forum.anna.partners/hunter/32/8_2.png) [@hunter](https://forum.anna.partners/u/hunter)\
**Post date:** [September 25, 2026, 4:18am UTC](https://forum.anna.partners/t/feature-request-let-scoped-frame-src-in-csp-overrides-or-a-native-video-playback-host-api/343/2 "2026-09-25T04:18:49Z")

</div>

Hi @Ilaye 👋

First off — we’re really sorry for the late response. 🙏 You’ve raised this more than once, and you absolutely deserved a reply sooner. Thank you for your patience and for taking the time to write it up so clearly each time.

Good news: **we’ve received this request, along with your earlier posts on the same topic.** ✅ The use case makes total sense — in-window playback of cited video moments is exactly the kind of experience we want Anna Apps to enable, and your write-up of the two possible paths (scoped `frame-src` in `csp_overrides` vs. a host-mediated playback API) is genuinely helpful input.

Our team is actively working on how best to support this. 🛠 Since it touches the App sandbox security model, we want to get it right rather than rush it — but it’s on our radar and moving.

**We’ll post an update right here in this thread once there’s something concrete to share.** 📬

Thanks again for building on Anna and for pushing us to make the platform better — feedback like yours is exactly what shapes it. 💛

---

<div class="post-metadata">

**Author:** ![hunter](https://yyz1.discourse-cdn.com/flex033/user_avatar/forum.anna.partners/hunter/32/8_2.png) [@hunter](https://forum.anna.partners/u/hunter)\
**Post date:** [September 25, 2026, 8:25am UTC](https://forum.anna.partners/t/feature-request-let-scoped-frame-src-in-csp-overrides-or-a-native-video-playback-host-api/343/3 "2026-09-25T08:25:27Z")

</div>

Hi @Ilaye 👋

First — a sincere apology for how long it took to get a proper response to this. You’ve raised it multiple times, and you deserved an answer sooner. Thank you for your patience and for the exceptionally clear write-up. 🙏

**Good news: this is done, and it ships today (Friday)!** 🎉

## What’s changing

✅ **`frame-src` is now supported in `ui.csp_overrides`** — exactly the way you proposed: an explicit allowlist of `https://` origins, scoped the same way `external_origins` already works (no wildcards, no open directive, up to 8 origins).

```json
"ui": {
  "csp_overrides": {
    "frame-src": ["https://www.youtube-nocookie.com"]
  }
}

```

## And a bit more you didn’t ask for (but would have hit next) 😄

While implementing this, we found two more walls behind the CSP one, and fixed both:

🎬 **Permissions-Policy delegation** — declaring `frame-src` now automatically delegates `autoplay`, `encrypted-media`, `fullscreen`, and `picture-in-picture` to your declared origins, through the whole chain. Without this, the player would render but fullscreen and autoplay-after-timestamp-jump (your core use case!) would silently fail. One thing you still do on your side: add the `allow` attribute to your own embed iframe:

```html
<iframe
  src="https://www.youtube-nocookie.com/embed/VIDEO_ID?start=42"
  allow="autoplay; encrypted-media; fullscreen; picture-in-picture">
</iframe>

```

🔗 **Referrer-Policy** — YouTube embeds require a `Referer` to validate the embedding origin. Apps that declare `frame-src` now get `strict-origin-when-cross-origin` on bundle assets (origin only, no paths leaked). Tip: don’t add `referrerpolicy="no-referrer"` to your embed iframe, or the player will fail with error 153.

## How to get it

- 🚀 Platform update rolls out **today**
- 📦 Then update the CLI: `@anna-ai/cli@0.1.56`
- 📚 Docs: the **app-ui-manifest** page has a new “Embedding third-party content (frame-src)” section
- 🧩 Working example: `anna-app-frame-embed-demo` in the examples repo — a minimal app embedding a video player with timestamp-jump buttons (your exact scenario)

⚠ One parity note: the **local harness does not simulate CSP or Permissions-Policy headers** , so an embed that works locally isn’t proof it will work in production. Please rely on `anna-app validate` and a working draft on the platform for final verification.

## On the native video-playback host API

We considered it, but decided against it (for now): YouTube’s ToS requires the official iframe player anyway, so a host-mediated component would face the same embedding constraints — just moved to our page instead of yours — while locking the solution to video. Scoped `frame-src` solves the general case: maps, players, document previews, any explicitly-declared third-party embed. 🗺📹📄

Really looking forward to seeing the YouTube research assistant in the store — jumping to cited timestamps in-window sounds genuinely delightful. If anything doesn’t behave as described once this lands, post here and we’ll jump on it fast. 💙

---

<div class="post-metadata">

**Author:** ![Ilaye](https://avatars.discourse-cdn.com/v4/letter/i/e480ec/32.png) [@Ilaye](https://forum.anna.partners/u/Ilaye)\
**Post date:** [September 26, 2026, 12:30pm UTC](https://forum.anna.partners/t/feature-request-let-scoped-frame-src-in-csp-overrides-or-a-native-video-playback-host-api/343/4 "2026-09-26T12:30:42Z")

</div>

Thank you so much. I sincerely appreciate the effort.
