* Add guard against DNS rebinding attacks * Fix not to apply to test environment
* Set CSP rules in RoR's configuration * Override CSP setting in the embed controller to allow frames