Cached · just now
10 directives

Content-Security-Policy

default-src Keyword —
'self'
default-src Keyword —
'unsafe-inline'
default-src Keyword —
'unsafe-eval'
default-src Scheme —
data:
default-src Scheme —
https:
default-src Scheme —
blob:
default-src Scheme —
wss:
sandbox Keyword —
allow-forms
sandbox Keyword —
allow-same-origin
sandbox Keyword —
allow-scripts
sandbox Keyword —
allow-popups
sandbox Keyword —
allow-popups-to-escape-sandbox
sandbox Keyword —
allow-top-navigation-by-user-activation
sandbox Keyword —
allow-presentation
sandbox Keyword —
allow-storage-access-by-user-activation
worker-src Keyword —
'self'
worker-src Scheme —
blob:
manifest-src Keyword —
'self'
font-src Keyword —
'self'
font-src Scheme —
data:
frame-ancestors Keyword —
'self'
frame-ancestors Host —
ASN | Amazon
frame-src Keyword —
'self'
frame-src Scheme —
https:
report-to Host —

Content-Security-Policy-Report-Only

No report-only CSP headers found.