Open
Cached
·
just now
8
directives
Content-Security-Policy
Content-Security-Policy: script-src 'sha256-MhtPZXr7+LpJUY5qtMutB+qWfQtMaPccfe7QXtCcEYc=' 'nonce-1OQGBALh-a1X5jn0EluLHQ' 'report-sample' 'strict-dynamic' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' http: https:; object-src 'self' https://edu.google.com; img-src * data:; connect-src 'self' *.analytics.google.com *.doubleclick.net *.google-analytics.com *.googleapis.com *.googleoptimize.com *.googletagmanager.com *.googleusercontent.com https://adservice.google.com https://analytics.google.com https://apis.google.com https://auditrecording-pa.googleapis.com https://cse.google.com https://directory-service-dot-gweb-edu-activity-app.appspot.com https://marketo-submit-787862449254.us-central1.run.app https://marketo-submit-dev-787862449254.us-central1.run.app https://optimize.google.com https://us-central1-gweb-cloudx-marketo.cloudfunctions.net https://us-central1-xl-chrome-enterprise-staging.cloudfunctions.net https://us-central1-xl-gfe-prod.cloudfunctions.net https://www.google-analytics.com https://www.google.com https://www.googleadservices.com https://www.gstatic.com https://www.youtube.com; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/edu_google; base-uri 'self'
script-src
Hash
—
'sha256-MhtPZXr7+LpJUY5qtMutB+qWfQtMaPccfe7QXtCcEYc='
script-src
Nonce
—
'nonce-1OQGBALh-a1X5jn0EluLHQ'
script-src
Keyword
—
'report-sample'
script-src
Keyword
—
'strict-dynamic'
script-src
Keyword
—
'unsafe-eval'
script-src
Keyword
—
'unsafe-hashes'
script-src
Keyword
—
'unsafe-inline'
script-src
Scheme
—
http:
script-src
Scheme
—
https:
object-src
Keyword
—
'self'
img-src
Host
—
*
img-src
Scheme
—
data:
connect-src
Keyword
—
'self'
base-uri
Keyword
—
'self'
Content-Security-Policy-Report-Only
Content-Security-Policy-Report-Only: require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/edu_google
require-trusted-types-for
Keyword
—
'script'