Open
Cached
·
just now
10
directives
Content-Security-Policy
Content-Security-Policy: default-src 'self' 'unsafe-inline' 'unsafe-eval' data: https: https://sb.scorecardresearch.com https://*.yahoo.com blob: wss:; sandbox allow-forms allow-same-origin allow-scripts allow-popups allow-popups-to-escape-sandbox allow-top-navigation-by-user-activation allow-presentation allow-storage-access-by-user-activation; object-src https://*.engadget.com https://s.yimg.com https://api.cloudinary.com https://o.aolcdn.com; worker-src 'self' blob:; manifest-src 'self' https://s.yimg.com; font-src 'self' data: https://*.engadget.com https://s.yimg.com https://fonts.gstatic.com https://*.spot.im https://assets.video.yahoo.net https://cdn.taboola.com; frame-ancestors 'self' https://*.engadget.com https://*.oath.com https://*.yahoo.com; frame-src 'self' https: https://login.yahoo.com https://gcp.stage.login.yahoo.com; report-uri https://csp.yahoo.com/beacon/csp?src=commerce; report-to csp-endpoint;
default-src
Keyword
—
'self'
default-src
Keyword
—
'unsafe-inline'
default-src
Keyword
—
'unsafe-eval'
default-src
Scheme
—
data:
default-src
Scheme
—
https:
default-src
Scheme
—
blob:
default-src
Scheme
—
wss:
sandbox
Keyword
—
allow-forms
sandbox
Keyword
—
allow-same-origin
sandbox
Keyword
—
allow-scripts
sandbox
Keyword
—
allow-popups
sandbox
Keyword
—
allow-popups-to-escape-sandbox
sandbox
Keyword
—
allow-top-navigation-by-user-activation
sandbox
Keyword
—
allow-presentation
sandbox
Keyword
—
allow-storage-access-by-user-activation
worker-src
Keyword
—
'self'
worker-src
Scheme
—
blob:
manifest-src
Keyword
—
'self'
font-src
Keyword
—
'self'
font-src
Scheme
—
data:
frame-ancestors
Keyword
—
'self'
frame-src
Keyword
—
'self'
frame-src
Scheme
—
https:
report-to
Host
—
Content-Security-Policy-Report-Only
No report-only CSP headers found.