Open
Cached
·
just now
16
directives
Content-Security-Policy
Content-Security-Policy: default-src 'self' *.launchdarkly.com *.ada.support *.ada-dev.support *.ada-dev2.support *.ada-stage.support headway-widget.net browser-intake-datadoghq.com *.browser-intake-datadoghq.com *.ada.cx https://*.chameleon.io; connect-src 'unsafe-inline' *.posthog.com *.launchdarkly.com *.ada.support *.ada-dev.support *.ada-dev2.support *.ada-stage.support *.datadoghq.com datadog.com browser-intake-datadoghq.com *.browser-intake-datadoghq.com *.pusher.com wss://*.pusher.com sentry.io *.sentry.io *.okta.com *.vidyard.com *.ada.cx *.hubapi.com *.hscollectedforms.net *.hubspot.com https://*.chameleon.io; frame-src 'self' ada.cx *.ada.cx *.ada.support *.ada-dev.support *.ada-dev2.support *.ada-stage.support *.okta.com *.vidyard.com *.wistia.com https://fast.wistia.net https://headway-widget.net https://form.typeform.com https://app.svix.com https://*.chameleon.io https://www.youtube.com; base-uri 'self'; block-all-mixed-content; font-src 'self' https: data:; form-action 'self'; frame-ancestors 'self' *.ada.support; img-src 'self' https: data: https://*.chameleon.io blob:; media-src 'self' https: blob:; script-src 'unsafe-inline' *.launchdarkly.com *.ada.support *.ada-dev.support *.ada-dev2.support *.ada-stage.support blob: *.posthog.com *.headwayapp.co https://*.chameleon.io; script-src-attr 'none'; script-src-elem 'unsafe-inline' *.ada.cx *.ada.support *.ada-dev.support *.ada-dev2.support *.ada-stage.support *.posthog.com *.headwayapp.co *.storage.googleapis.com *.hs-scripts.com *.hs-banner.com *.hscollectedforms.net *.hs-analytics.net *.hscollectedforms.net *.hsadspixel.net *.hsleadflows.net *.hubspot.com https://*.chameleon.io; style-src 'self' https: 'unsafe-inline'; upgrade-insecure-requests; report-uri https://o38990.ingest.sentry.io/api/97224/security/?sentry_key=4e7b13b67aea4b12ada7bf728e8b3a7a;
default-src
Keyword
—
'self'
default-src
Host
—
default-src
Host
—
default-src
Host
—
connect-src
Keyword
—
'unsafe-inline'
connect-src
Host
—
connect-src
Host
—
connect-src
Host
—
frame-src
Keyword
—
'self'
frame-src
Host
—
frame-src
Host
—
frame-src
Host
—
base-uri
Keyword
—
'self'
block-all-mixed-content
Source
—
(no sources)
font-src
Keyword
—
'self'
font-src
Scheme
—
https:
font-src
Scheme
—
data:
form-action
Keyword
—
'self'
frame-ancestors
Keyword
—
'self'
img-src
Keyword
—
'self'
img-src
Scheme
—
https:
img-src
Scheme
—
data:
img-src
Scheme
—
blob:
media-src
Keyword
—
'self'
media-src
Scheme
—
https:
media-src
Scheme
—
blob:
script-src
Keyword
—
'unsafe-inline'
script-src
Host
—
script-src
Host
—
script-src
Host
—
script-src
Scheme
—
blob:
script-src-attr
Keyword
—
'none'
script-src-elem
Keyword
—
'unsafe-inline'
script-src-elem
Host
—
script-src-elem
Host
—
script-src-elem
Host
—
style-src
Keyword
—
'self'
style-src
Scheme
—
https:
style-src
Keyword
—
'unsafe-inline'
upgrade-insecure-requests
Source
—
(no sources)
Content-Security-Policy-Report-Only
No report-only CSP headers found.