Open
Cached
·
9h ago
12
directives
Content-Security-Policy
No enforced CSP headers found.
Content-Security-Policy-Report-Only
Content-Security-Policy-Report-Only: script-src 'self' 'unsafe-inline' 'unsafe-eval' https://analytics.google.com https://bat.bing.com https://cdn.cookielaw.org https://app.pendo.io https://cdn.pendo.io https://cdn.segment.com https://cdn.walkme.com https://cdnssl.clicktale.net https://data.pendo.io https://ds-aksb-a.akamaihd.net https://nexus.ensighten.com https://siteintercept.qualtrics.com https://www.glancecdn.net https://www.googletagmanager.com https://*.clicktale.net https://*.cloudflare.com https://*.facebook.net https://*.fidelity.com https://*.fmr.com https://*.glancecdn.net https://*.online-metrix.net https://*.segment.com https://*.siteintercept.qualtrics.com https://siteintercept.qualtrics.com; script-src-elem 'self' 'unsafe-inline' https://analytics.google.com https://bat.bing.com https://cdn.cookielaw.org https://app.pendo.io https://cdn.pendo.io https://cdn.segment.com https://cdn.walkme.com https://cdnssl.clicktale.net https://data.pendo.io https://ds-aksb-a.akamaihd.net https://nexus.ensighten.com https://siteintercept.qualtrics.com https://www.glancecdn.net https://www.googletagmanager.com https://*.clicktale.net https://*.cloudflare.com https://*.facebook.net https://*.fidelity.com https://*.fmr.com https://*.glancecdn.net https://*.online-metrix.net https://*.segment.com https://*.siteintercept.qualtrics.com https://siteintercept.qualtrics.com; font-src 'self' data: *; img-src 'self' data: blob: *; media-src 'self' data: blob: *; connect-src 'self' blob: data: * chrome-extension: moz-extension:; child-src 'self' blob: *; frame-src 'self' blob: *; style-src 'unsafe-inline' *; worker-src 'self' blob:; default-src *; report-uri https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubdbe43cdb0fed70b9575444d8ad225b0d&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=service%3Aap118909-digital%2Cenv%3Aprod%2Cfid_index_id%3Acsp-prod
script-src
Keyword
—
'self'
script-src
Keyword
—
'unsafe-inline'
script-src
Keyword
—
'unsafe-eval'
script-src
Host
—
script-src
Host
—
script-src-elem
Keyword
—
'self'
script-src-elem
Keyword
—
'unsafe-inline'
script-src-elem
Host
—
script-src-elem
Host
—
font-src
Keyword
—
'self'
font-src
Scheme
—
data:
font-src
Host
—
*
img-src
Keyword
—
'self'
img-src
Scheme
—
data:
img-src
Scheme
—
blob:
img-src
Host
—
*
media-src
Keyword
—
'self'
media-src
Scheme
—
data:
media-src
Scheme
—
blob:
media-src
Host
—
*
connect-src
Keyword
—
'self'
connect-src
Scheme
—
blob:
connect-src
Scheme
—
data:
connect-src
Host
—
*
connect-src
Scheme
—
chrome-extension:
connect-src
Scheme
—
moz-extension:
child-src
Keyword
—
'self'
child-src
Scheme
—
blob:
child-src
Host
—
*
frame-src
Keyword
—
'self'
frame-src
Scheme
—
blob:
frame-src
Host
—
*
style-src
Keyword
—
'unsafe-inline'
style-src
Host
—
*
worker-src
Keyword
—
'self'
worker-src
Scheme
—
blob:
default-src
Host
—
*