Use SPA SDK with Cross-Origin Embeder Policy

Hi all, we are using auth0-spa-js 1.13.6 in our application.

We require the SharedArrayBuffer in our application and therefore we need to set the Browser to cross-origin isolated by adding the following headers:
Cross-Origin-Opener-Policy: same-origin
Cross-Origin-Embedder-Policy: require-corp

See Making your website "cross-origin isolated" using COOP and COEP

This breaks the Auth0 SPA SDK, because there is a /authorize request running in an iframe. This iframe does not have any Cross-Origin Resource Policy set.

How could we solve this?

