Configuration
Config: Default Headless Frontend Base URL
opendxp_headless_toolbox:
default_headless_frontend_base_url: 'https://my-application.ch' # only required, if i18n bundle is not installed
Config: Dynamic Admin CSP Header
This bundle dynamically extends admin CSP handling (Content-Security-Policy response header of the admin).
For each OpenDXP site that should be added to the CSP frame-ancestors directive, enable the "Add Main Domain to CSP Header" checkbox in the site's custom settings:
Admin → Sites → [select site] → Custom Settings → Headless Toolbox → Add Domain to CSP