Open
Cached
·
just now
14
directives
Content-Security-Policy
Content-Security-Policy: default-src 'self' https://*.skool.sg https://*.myfirstskool.com https://*.littleskoolhouse.com https://*.amazonaws.com https://*.cloudfront.com https://*.cloudfront.net https://sn-image-service-dot-tcc-sn-dev.appspot.com https://*.go-mpulse.net https://*.google.com https://*.googleapis.com https://*.freshchat.com https://*.google-analytics.com https://*.googletagmanager.com stats.g.doubleclick.net ws: wss:; style-src https://*.freshdesk.com https://*.freshworks.com 'self' 'unsafe-inline' https://fonts.googleapis.com https://wchat.freshchat.com https://sn2-care-journal-stg.web.app https://sn2-whiteboard-stg.web.app; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.go-mpulse.net https://polyfill-fastly.io https://maps.googleapis.com https://wchat.freshchat.com https://www.google-analytics.com https://www.googletagmanager.com stats.g.doubleclick.net; object-src blob: 'self' *.amazonaws.com *.cloudfront.com *.cloudfront.net https://sn-image-service-dot-tcc-sn-dev.appspot.com *.skool.sg *.myfirstskool.com *.littleskoolhouse.com; img-src * 'self' data: *.amazonaws.com *.cloudfront.com *.cloudfront.net https://sn-image-service-dot-tcc-sn-dev.appspot.com *.skool.sg *.myfirstskool.com *.littleskoolhouse.com https://akstat.io; font-src * data: blob: fonts.googleapis.com fonts.gstatic.com; frame-ancestors https://www.parent.skool.sg https://parent.skool.sg https://www.parent.skooluat.sg https://parent.skooluat.sg https://www.myfirstskool.com https://myfirstskool.com; frame-src https://www.googletagmanager.com *.freshchat.com *.google.com blob: 'self' *.amazonaws.com *.cloudfront.com *.cloudfront.net https://sn-image-service-dot-tcc-sn-dev.appspot.com *.skool.sg *.myfirstskool.com *.littleskoolhouse.com https://sn2-care-journal-stg.web.app https://preprod-auth.ntuclink.com.sg; worker-src 'self' blob:; script-src-elem https://*.freshdesk.com https://*.freshworks.com 'self' 'unsafe-inline' blob: https://polyfill-fastly.io https://maps.googleapis.com https://wchat.freshchat.com https://www.google-analytics.com https://*.go-mpulse.net https://sn2-whiteboard-stg.web.app https://sn2-care-journal-stg.web.app https://sn2-care-journal-dev.web.app; form-action 'self' https://*.skool.sg https://*.myfirstskool.com https://*.littleskoolhouse.com https://preprod-auth.ntuclink.com.sg; base-uri 'self'; connect-src 'self' https://preprod-auth.ntuclink.com.sg https://*.akstat.io https://*.freshdesk.com https://*.freshworks.com 'self' https://*.skool.sg https://*.myfirstskool.com https://*.littleskoolhouse.com https://sn2-care-journal-stg.web.app https://sn2-whiteboard-stg.web.app https://*.amazonaws.com https://*.cloudfront.com https://*.cloudfront.net https://sn-image-service-dot-tcc-sn-dev.appspot.com https://*.go-mpulse.net https://*.google.com https://*.googleapis.com https://*.freshchat.com https://*.google-analytics.com https://*.googletagmanager.com stats.g.doubleclick.net https://*.split.io https://cloudflare-dns.com https://*.datadoghq.eu https://logs.browser-intake-datadoghq.eu https://rum.browser-intake-datadoghq.eu ws: wss:; report-to csp-endpoint;
default-src
Keyword
—
'self'
default-src
Host
—
default-src
Scheme
—
ws:
default-src
Scheme
—
wss:
style-src
Keyword
—
'self'
style-src
Keyword
—
'unsafe-inline'
script-src
Keyword
—
'self'
script-src
Keyword
—
'unsafe-inline'
script-src
Keyword
—
'unsafe-eval'
script-src
Host
—
object-src
Scheme
—
blob:
object-src
Keyword
—
'self'
img-src
Host
—
*
img-src
Keyword
—
'self'
img-src
Scheme
—
data:
img-src
Host
—
font-src
Host
—
*
font-src
Scheme
—
data:
font-src
Scheme
—
blob:
frame-ancestors
Host
—
frame-ancestors
Host
—
frame-ancestors
Host
—
frame-src
Scheme
—
blob:
frame-src
Keyword
—
'self'
worker-src
Keyword
—
'self'
worker-src
Scheme
—
blob:
script-src-elem
Keyword
—
'self'
script-src-elem
Keyword
—
'unsafe-inline'
script-src-elem
Scheme
—
blob:
script-src-elem
Host
—
form-action
Keyword
—
'self'
base-uri
Keyword
—
'self'
connect-src
Keyword
—
'self'
connect-src
Host
—
connect-src
Keyword
—
'self'
connect-src
Host
—
connect-src
Scheme
—
ws:
connect-src
Scheme
—
wss:
report-to
Host
—
Content-Security-Policy-Report-Only
No report-only CSP headers found.