<html>
    <head>
      <base href="https://bugs.webkit.org/" />
    </head>
    <body><table border="1" cellspacing="0" cellpadding="8">
        <tr>
          <th>Bug ID</th>
          <td><a class="bz_bug_link 
          bz_status_NEW "
   title="NEW - Deprecate/remove support for X-Frame-Options in `&lt;meta&gt;`"
   href="https://bugs.webkit.org/show_bug.cgi?id=156625">156625</a>
          </td>
        </tr>

        <tr>
          <th>Summary</th>
          <td>Deprecate/remove support for X-Frame-Options in `&lt;meta&gt;`
          </td>
        </tr>

        <tr>
          <th>Classification</th>
          <td>Unclassified
          </td>
        </tr>

        <tr>
          <th>Product</th>
          <td>WebKit
          </td>
        </tr>

        <tr>
          <th>Version</th>
          <td>WebKit Nightly Build
          </td>
        </tr>

        <tr>
          <th>Hardware</th>
          <td>Unspecified
          </td>
        </tr>

        <tr>
          <th>OS</th>
          <td>Unspecified
          </td>
        </tr>

        <tr>
          <th>Status</th>
          <td>NEW
          </td>
        </tr>

        <tr>
          <th>Severity</th>
          <td>Normal
          </td>
        </tr>

        <tr>
          <th>Priority</th>
          <td>P2
          </td>
        </tr>

        <tr>
          <th>Component</th>
          <td>WebCore Misc.
          </td>
        </tr>

        <tr>
          <th>Assignee</th>
          <td>webkit-unassigned&#64;lists.webkit.org
          </td>
        </tr>

        <tr>
          <th>Reporter</th>
          <td>mkwst&#64;chromium.org
          </td>
        </tr></table>
      <p>
        <div>
        <pre>Firefox and Edge follow the RFC's suggestion (<a href="https://tools.ietf.org/html/rfc7034#section-4">https://tools.ietf.org/html/rfc7034#section-4</a>) to ignore the 'X-Frame-Options' header when delivered as `&lt;meta http-equiv=&quot;...&quot;&gt;` (and have done so from their initial implementations).

Blink has just removed this functionality (<a href="https://crbug.com/603002">https://crbug.com/603002</a>). The risks were outlined in <a href="https://groups.google.com/a/chromium.org/forum/#!topic/blink-dev/R1gkjKZI0J8">https://groups.google.com/a/chromium.org/forum/#!topic/blink-dev/R1gkjKZI0J8</a>, and seem minimal (~150 domains use the feature, period).

Perhaps WebKit could consider removing support as well?</pre>
        </div>
      </p>
      <hr>
      <span>You are receiving this mail because:</span>
      
      <ul>
          <li>You are the assignee for the bug.</li>
      </ul>
    </body>
</html>