Refused to display 'https://gitlab.com/' in a frame because an ancestor violates the following Content Security Policy directive: "frame-ancestors 'self'".
检查发现是网站响应头内容安全策略限制(Content-Security-Policy)原因
Content-Security-Policy: connect-src 'self'
connect-src 'self' 会禁止iframe嵌入自己的网页