Open
Cached
·
just now
9
directives
Content-Security-Policy
Content-Security-Policy: script-src 'self' 'unsafe-inline' cdn.segment.com www.googletagmanager.com www.google-analytics.com *.hs-analytics.net *.hs-scripts.com *.hsadspixel.net *.hs-banner.com connect.facebook.net *.fullstory.com cdnjs.cloudflare.com *.frontapp.com ; style-src 'self' 'unsafe-inline' blob: fonts.googleapis.com ; img-src 'self' data: * ; font-src 'self' data: fonts.gstatic.com *.frontapp.com fonts.cdnfonts.com ; connect-src 'self' *.upwave.com shareofsearch.net d3hb14vkzrxvla.cloudfront.net cdn.segment.com api.segment.io cdn.optimizely.com *.google-analytics.com o72721.ingest.sentry.io beaconapi.helpscout.net upwave.okta.com upwave.oktapreview.com global.oktacdn.com *.fullstory.com *.hubapi.com www.facebook.com stats.g.doubleclick.net wss://front-us-realtime.ably.io wss://front-eu-realtime.ably.io internet-up.ably-realtime.com *.frontapp.com *.bugsnag.com *.browser-intake-datadoghq.com www.googletagmanager.com ; frame-src 'self' www.upwave.com app.csvbox.io www.facebook.com secure-ds.serving-sys.com drive.google.com ; default-src 'self' data: blob: ; report-to default ; report-uri https://upwave.report-uri.com/r/d/csp/enforce
script-src
Keyword
—
'self'
script-src
Keyword
—
'unsafe-inline'
style-src
Keyword
—
'self'
style-src
Keyword
—
'unsafe-inline'
style-src
Scheme
—
blob:
img-src
Keyword
—
'self'
img-src
Scheme
—
data:
img-src
Host
—
*
font-src
Keyword
—
'self'
font-src
Scheme
—
data:
connect-src
Keyword
—
'self'
frame-src
Keyword
—
'self'
frame-src
Host
—
default-src
Keyword
—
'self'
default-src
Scheme
—
data:
default-src
Scheme
—
blob:
report-to
Host
—
Content-Security-Policy-Report-Only
No report-only CSP headers found.