Permissions Policy sets policies with Permissions-Policy and allow. Chromium 4,389 (Chrome 74 1 ) exposes the result as document.featurePolicy with allowsFeature(), features() and allowedFeatures(); Firefox 555 and Safari 10 lack it, so treat absence as "unknown". Blocked calls fail and queue a permissions-policy-violation report.
<pre id="out" style="font: 14px/1.5 monospace; margin: 0"></pre>
<script>
const say = (text) => { out.textContent += text + '\n'; };
const frame = Object.assign(document.createElement('iframe'),
{ allow: "camera 'none'; geolocation 'none'", srcdoc: 'widget', hidden: true });
frame.onload = () => {
const win = frame.contentWindow;
new win.ReportingObserver(([r]) => say(`report: ${r.type} ${r.body.featureId}`)).observe();
say(`frame allows camera: ${win.document.featurePolicy.allowsFeature('camera')}`);
win.navigator.geolocation.getCurrentPosition(() => {},
(e) => say(`geolocation error ${e.code}`));
};
document.body.append(frame);
</script>
A policy is not a permission: the user may still block an allowed camera (Permissions API).