Open
Cached
·
just now
5
directives
Content-Security-Policy
Content-Security-Policy: base-uri 'self';object-src none;script-src 'self' 'nonce-pyJu9XpUb0htfAGJkEYjSMKvHdmgYhv6' https://accounts.google.com https://www.google.com https://www.gstatic.com https://*.smooch.io https://static.zdassets.com/messaging/sunco-frontend-assets/dashboard/ https://checkout.stripe.com https://stripe.com 'unsafe-eval' 'unsafe-inline' https://www.youtube.com https://*.zendesk.com https://static.zdassets.com;frame-ancestors 'self';report-uri https://o1025743.ingest.sentry.io/api/6184622/security/?sentry_key=7fa93775fdec4123a149cb5fbd4e7822&sentry_environment=production
base-uri
Keyword
—
'self'
object-src
Host
—
script-src
Keyword
—
'self'
script-src
Nonce
—
'nonce-pyJu9XpUb0htfAGJkEYjSMKvHdmgYhv6'
script-src
Keyword
—
'unsafe-eval'
script-src
Keyword
—
'unsafe-inline'
frame-ancestors
Keyword
—
'self'
Content-Security-Policy-Report-Only
No report-only CSP headers found.