@@ -84909,6 +84909,50 @@ interface <dfn>BeforeUnloadEvent</dfn> : <span>Event</span> {
8490984909 </li>
8491084910 </ol>
8491184911
84912+ <hr>
84913+
84914+ </div>
84915+
84916+ <div class="example">
84917+ <p>The following table illustrates the processing of various values for the header, including
84918+ nonconformant ones:</p>
84919+
84920+ <table class="data">
84921+ <thead>
84922+ <tr>
84923+ <th>`<code>X-Frame-Options</code>`</th>
84924+ <th>Valid</th>
84925+ <th>Result</th>
84926+ </tr>
84927+ </thead>
84928+ <tbody>
84929+ <tr>
84930+ <td>`<code data-x="">DENY</code>`</td>
84931+ <td>✅</td>
84932+ <td>embedding disallowed</td>
84933+ </tr>
84934+ <tr>
84935+ <td>`<code data-x="">SAMEORIGIN</code>`</td>
84936+ <td>✅</td>
84937+ <td>same-origin embedding allowed</td>
84938+ </tr>
84939+ <tr>
84940+ <td>`<code data-x="">INVALID</code>`</td>
84941+ <td>❌</td>
84942+ <td>embedding allowed</td>
84943+ </tr>
84944+ <tr>
84945+ <td>`<code data-x="">ALLOWALL</code>`</td>
84946+ <td>❌</td>
84947+ <td>embedding allowed</td>
84948+ </tr>
84949+ <tr>
84950+ <td>`<code data-x="">ALLOW-FROM=https://example.com/</code>`</td>
84951+ <td>❌</td>
84952+ <td>embedding allowed (from anywhere)</td>
84953+ </tr>
84954+ </tbody>
84955+ </table>
8491284956 </div>
8491384957
8491484958 <div class="example">
@@ -84931,6 +84975,10 @@ interface <dfn>BeforeUnloadEvent</dfn> : <span>Event</span> {
8493184975 <td>`<code data-x="">SAMEORIGIN, DENY</code>`</td>
8493284976 <td>embedding disallowed</td>
8493384977 </tr>
84978+ <tr>
84979+ <td>`<code data-x="">SAMEORIGIN,</code>`</td>
84980+ <td>embedding disallowed</td>
84981+ </tr>
8493484982 <tr>
8493584983 <td>`<code data-x="">SAMEORIGIN, ALLOWALL</code>`</td>
8493684984 <td>embedding disallowed</td>
@@ -84943,6 +84991,10 @@ interface <dfn>BeforeUnloadEvent</dfn> : <span>Event</span> {
8494384991 <td>`<code data-x="">ALLOWALL, INVALID</code>`</td>
8494484992 <td>embedding disallowed</td>
8494584993 </tr>
84994+ <tr>
84995+ <td>`<code data-x="">ALLOWALL,</code>`</td>
84996+ <td>embedding disallowed</td>
84997+ </tr>
8494684998 <tr>
8494784999 <td>`<code data-x="">INVALID, INVALID</code>`</td>
8494885000 <td>embedding allowed</td>
0 commit comments