Cross-Origin Embedder Policy (COEP)

COEP ensures that resources loaded from other sources have explicitly given permission to be embedded.

It can protect from embedding unwanted:

  • <script src="https://example.com/script.js"></script>
  • <img src="https://example.com/image.png">
  • <iframe src="https://example.com"></iframe>
  • <video>, <audio>, <link rel="stylesheet">, <object>, <embed>

References