4 directives

Content-Security-Policy

default-src Keyword 'none'
style-src Keyword 'unsafe-inline'
img-src Scheme data:
connect-src Keyword 'self'

Content-Security-Policy-Report-Only

No report-only CSP headers found.