Embed CSP test page (DEMO). Pretend third-party site. Developer docs · frames blocked · script blocked · allowed

Strict CSP that allows our origins

This page is served with the header:
Content-Security-Policy: default-src 'none'; script-src https://demo.atlasag.co https://trades-request-demo.vercel.app; frame-src https://demo.atlasag.co https://trades-request-demo.vercel.app; style-src 'self'; img-src 'self'; base-uri 'none'; form-action 'none'
Expected: the embedded form loads and works normally. Note there's no 'unsafe-inline' anywhere: the embed needs none.