A customer site embedding vewo
Served from , which is a real third-party origin. Whatever
happens below happens because of the domain rules, not because a header was forged.
The iframe embed
The documented snippet, unmodified. If the workspace allowlist does not include this domain, a working domain lock should refuse to play here.
What this page's own origin reports
The iframe runs on vewo.io, so the Referer vewo's API receives is vewo.io and not this page. These are the values an embed would have to forward for a lock to see the truth.
—
Webhook deliveries received here
POST /hook verifies the signature with the shared secret.
—