Strict CSP that allows our origins
This page is served with the header:Content-Security-Policy: default-src 'none'; script-src https://demo.atlasag.co https://trades-request-demo.vercel.app; frame-src https://demo.atlasag.co https://trades-request-demo.vercel.app; style-src 'self'; img-src 'self'; base-uri 'none'; form-action 'none'
Expected: the embedded form loads and works normally. Note there's no 'unsafe-inline' anywhere: the embed needs none.