Hello,
stststst I imagine it might be difficult with the requirement for two domains?
Indeed, you got it right, it's not currently possible to do it properly due to the 2 domains requirements.
We could be able to lift this in the future, by implementing other security practices, but we don't have a clear roadmap to share for this.