Widget origin under test: https://chat.dev.thejaine.ai
Each link below serves the partner's captured Content-Security-Policy as a response header, with one directive changed. Open the browser console and watch the violation box above.
/resources — (default — the captured policy verbatim)/resources?blob=1 — blob: allowed on object-src / frame-src/resources?widget-origin=0 — widget origin removed from object-src / frame-src/resources?s3=0 — S3 document bucket removed/resources?snippet-nonce=1 — nonce passed to the widget script tag/resources?style-src-elem=0 — style-src-elem removed, so style-src governs <style>/resources?report-only=1 — served Report-Only/resources?coep=1 — COEP require-corp added/survey/123 — (default — the captured policy verbatim)/survey/123?blob=1 — blob: allowed on object-src / frame-src/survey/123?widget-origin=0 — widget origin removed from object-src / frame-src/survey/123?s3=0 — S3 document bucket removed/survey/123?snippet-nonce=1 — nonce passed to the widget script tag/survey/123?style-src-elem=0 — style-src-elem removed, so style-src governs <style>/survey/123?report-only=1 — served Report-Only/survey/123?coep=1 — COEP require-corp added