I'm looking for a method that will only allow a page to be opened in an iframe and not in a main browser window. I know I can check the parent using Javascript but that is easily defeated - ideally I'm looking for a Content-Security-Policy header or similar that browsers will obey (I know they can be defeated too but I can live with that risk).