?embed=<widget> to an event’s public URL to get one section with none of
the page chrome, sized for an iframe:
Appearance
theme=light|dark|auto, accent=<6 hex digits, no #>, and branding=0 to hide
the “Powered by smolboard” line.
Framing
Embed responses sendContent-Security-Policy: frame-ancestors *, so they can
be framed from any origin. The rest of the app keeps the default SAMEORIGIN.
These surfaces are anonymous and read only published, approved content. You
can put one on a public marketing site without exposing anything an attendee
could not already see.