Open
Cached
·
just now
12
directives
Content-Security-Policy
Content-Security-Policy: default-src 'self' https://*.zopim.com wss://*.zopim.com https://*.zendesk.com https://*.zdassets.com https://*.statuspage.io https://zendesk-eu.my.sentry.io https://pf-prontoforms-public-resources.s3.amazonaws.com https://*.prontoforms.com https://*.truecontext.com https://*.wistia.net https://*.google.com https://www.youtube.com https://*.salesforce.com https://*.salesforce-scrt.com https://*.force.com https://*.my.site.com; style-src 'self' 'unsafe-inline' https://*.gstatic.com https://*.googleapis.com https://*.zdassets.com https://*.tinymce.com https://insights.prontoforms.com https://cdn.qrvey.com https://*.salesforce.com https://*.force.com https://*.my.site.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.newrelic.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.zopim.com https://*.statuspage.io https://*.wistia.com https://*.wistia.net https://*.zendesk.com https://*.zdassets.com https://*.nr-data.net https://*.prontoforms.com https://*.salesforce.com https://*.salesforce-scrt.com https://*.force.com https://*.my.site.com; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https://*.newrelic.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.zopim.com https://*.statuspage.io https://*.wistia.com https://*.wistia.net https://*.zendesk.com https://*.zdassets.com https://*.nr-data.net https://*.prontoforms.com https://*.salesforce.com https://*.salesforce-scrt.com https://*.force.com https://*.my.site.com; img-src 'self' https://*.gstatic.com https://prontoforms-public-resources.s3.amazonaws.com https://pf-prontoforms-public-resources.s3.amazonaws.com https://*.google.com http://chart.apis.google.com https://v2assets.zopim.io https://*.truecontext.com https://*.googleapis.com https://*.googleusercontent.com https://*.zendesk.com https://*.prontoforms.com https://*.zdassets.com https://*.app.box.com https://*.nr-data.net https://prontoforms.com https://cdn.redoc.ly https://truecontext.com https://insights.prontoforms.com https://*.salesforce.com https://*.force.com https://*.my.site.com data:; font-src 'self' https://*.gstatic.com https://insights.prontoforms.com https://cdn.qrvey.com https://*.salesforce.com https://*.force.com https://*.my.site.com data:; connect-src 'self' https://*.nr-data.net https://*.zendesk.com wss://truecontext.zendesk.com https://*.googleapis.com https://*.wistia.com https://*.truecontext.com https://*.zdassets.com https://zendesk-eu.my.sentry.io https://*.zopim.com wss://*.zopim.com https://*.prontoforms.com https://*.google.com https://cognito-identity.us-east-1.amazonaws.com https://insights.prontoforms.com https://maps.geo.us-east-1.amazonaws.com https://*.salesforce.com https://*.salesforce-scrt.com https://*.force.com https://*.my.site.com wss://*.salesforce.com wss://*.force.com wss://*.my.site.com; media-src 'self' https://*.zdassets.com https://*.salesforce.com https://*.force.com https://*.my.site.com data:; frame-src 'self' https://*.zopim.com wss://*.zopim.com https://*.zendesk.com https://*.zdassets.com https://*.statuspage.io https://zendesk-eu.my.sentry.io https://pf-prontoforms-public-resources.s3.amazonaws.com https://*.prontoforms.com https://*.truecontext.com https://*.wistia.net https://*.google.com https://www.youtube.com https://*.salesforce.com https://*.force.com https://*.my.site.com; frame-ancestors 'self'; worker-src blob:; report-uri https://live.prontoforms.com/pageapi/1/log;
default-src
Keyword
—
'self'
default-src
Host
—
style-src
Keyword
—
'self'
style-src
Keyword
—
'unsafe-inline'
style-src
Host
—
script-src
Keyword
—
'self'
script-src
Keyword
—
'unsafe-inline'
script-src
Keyword
—
'unsafe-eval'
script-src
Host
—
script-src
Host
—
script-src-elem
Keyword
—
'self'
script-src-elem
Keyword
—
'unsafe-inline'
script-src-elem
Keyword
—
'unsafe-eval'
script-src-elem
Host
—
script-src-elem
Host
—
img-src
Keyword
—
'self'
img-src
Host
—
img-src
Host
—
img-src
Host
—
img-src
Scheme
—
data:
font-src
Keyword
—
'self'
font-src
Scheme
—
data:
connect-src
Keyword
—
'self'
connect-src
Host
—
connect-src
Host
—
media-src
Keyword
—
'self'
media-src
Host
—
media-src
Scheme
—
data:
frame-src
Keyword
—
'self'
frame-src
Host
—
frame-ancestors
Keyword
—
'self'
worker-src
Scheme
—
blob:
Content-Security-Policy-Report-Only
No report-only CSP headers found.