Vaultwarden sends a restrictive Content-Security-Policy with frame-ancestors that blocks iframe embedding. The embed proxy (port 8890) already stripped this header, but the subdomain server block did not. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>