**Fixed Open Graph Image Issues:**
- Updated static asset handling in security middleware
- Removed CSP restrictions for /static/ paths to allow social media scrapers
- Added proper cache headers for static assets (1 year cache)
- Fixed og:image dimensions to match actual image (1800x600)
- Added og:image:alt attribute for accessibility
- Added cache-busting version parameter (?v=2) to force preview refresh
**Added Debug Test Page:**
- Created /test-og/ endpoint for testing social media previews
- Displays actual meta tag URLs and image preview
- Includes testing instructions and troubleshooting tips
**Root Cause:** CSP and security headers were blocking social media crawlers from accessing the og-image.png file
**Testing:** Visit /test-og/ and use Facebook/Twitter debugging tools to verify image previews work
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
- Smart detection for pages needing external iframe support
- Covers both direct access agents AND external wrapper pages
- Auto-detects event pages, forms, calendly, etc. from EXTERNAL_PAGES config
- Added comprehensive CSP whitelist for common services:
* JotForm (form.jotform.com, agent.jotform.com, cdn.jotfor.ms)
* Calendly (calendly.com, assets.calendly.com)
* Typeform (typeform.com, *.typeform.com)
* Airtable (airtable.com, *.airtable.com)
* HubSpot (hubspot.com, *.hubspot.com)
* Zapier (zapier.com, *.zapier.com)
* Google Analytics/GTM support
- Proper X-Frame-Options handling for iframe pages
- No more CSP blocking for current or future external integrations!
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>