Regression from #8957
* Set CSP rules in RoR's configuration * Override CSP setting in the embed controller to allow frames