#abignalet-iframe-3ds

1 messages · Page 1 of 1 (latest)

mellow yoke
#

the content of the iframe comes directly form the bank's "ACS" (3D Secure server) so it's kind of impossible to know what domain/origin that will be since it is entirely controlled by each cardholder's bank

#

you basically have to allow everything/a wildcard here, there isn't another option, as best as I'm aware

verbal nacelle
#

Okay, I was thinking the same. So removing the meta frame-src is wildcard you mean?

mellow yoke
#

I'd remove it entirely personally

verbal nacelle
#

Ok i'll try that