CSP for Tally Forms: Embed Options, Tradeoffs, and Fixes
If you embed Tally forms on a site with a serious Content Security Policy, you’ll hit friction fast. Tally is easy to drop into a page. CSP is not forgiving. That mismatch is where teams usually get stuck: the marketing team wants a form live in five minutes, and the security policy says “absolutely not” unless every source is accounted for. Here’s the practical guide I wish more teams had before they started whitelisting random domains. ...