Platform requirements
Most platforms need nothing beyond the snippet. The sections below cover the ones that enforce a Content-Security-Policy (CSP) or restrict embeds.
Content-Security-Policy
Section titled “Content-Security-Policy”If your site sends a CSP header, add the directives for the option you use.
frame-src https://www.edgeaifoundation.org;The iframe does not depend on any referrer setting.
script-src https://www.edgeaifoundation.org;connect-src https://www.edgeaifoundation.org;img-src https://import.cdn.thinkific.com https://d27aquackk44od.cloudfront.net;style-src 'unsafe-inline';The widget injects its own styles, so style-src must include 'unsafe-inline'. Course images load from Thinkific’s image CDN.
SharePoint Online
Section titled “SharePoint Online”Use the Embed web part with the iframe snippet.
- The site’s HTML Field Security settings must allow embedding from
www.edgeaifoundation.org. Otherwise the Embed web part refuses the iframe. - Register the SharePoint hostname with us, for example
contoso.sharepoint.com.
Microsoft Teams and Viva Connections
Section titled “Microsoft Teams and Viva Connections”If the SharePoint page is itself shown inside another app, every surrounding page must be registered too. Typical hostnames:
teams.microsoft.comteams.cloud.microsoft- your SharePoint tenant hostname
Confluence, ServiceNow and other portals
Section titled “Confluence, ServiceNow and other portals”Use the iframe snippet in the platform’s HTML or iframe macro. If the platform strips <script> tags, the iframe keeps a fixed height of 900 pixels. See Option A: iframe.