Some of the new HTTP headers are just a mess. Did you know that X-Frame-Options' Allow-From option only allows you to whitelist one URL? Not a domain - a URL. The RFC actually expects you to communicate via another channel to determine whether or not a URL will be allowed to frame your page.
Luckily, this one is still a draft...