How to decouple frontend and backend in Embedded App?

Update on this issue here: Configuring CSP for iframe protection