Open
Cached
·
just now
6
directives
Content-Security-Policy
Content-Security-Policy: script-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.googleapis.com https://*.bootstrapcdn.com https://www.googletagmanager.com https://code.jquery.com/jquery-3.6.0.min.js https://code.jquery.com/jquery-migrate-3.3.2.min.js https://az416426.vo.msecnd.net/scripts/a/ai.0.js https://cdn.syncfusion.com https://web-sdk.aptrinsic.com https://cdn.botframework.com/ everify.fiddletreesystems.com ; style-src 'self' 'unsafe-inline' blob: https://*.googleapis.com https://*.trimble.com https://web-sdk.aptrinsic.com ; object-src 'none' ; form-action 'self' ; frame-ancestors 'self' *.viewpointforcloud.com team.viewpoint.com https://*.viewpointforcloud.com https://team.viewpoint.com/ ; worker-src 'self' 'unsafe-inline' blob:;
script-src
Keyword
—
'self'
script-src
Keyword
—
'unsafe-eval'
script-src
Keyword
—
'unsafe-inline'
style-src
Keyword
—
'self'
style-src
Keyword
—
'unsafe-inline'
style-src
Scheme
—
blob:
style-src
Host
—
object-src
Keyword
—
'none'
form-action
Keyword
—
'self'
frame-ancestors
Keyword
—
'self'
frame-ancestors
Host
—
frame-ancestors
Host
—
worker-src
Keyword
—
'self'
worker-src
Keyword
—
'unsafe-inline'
worker-src
Scheme
—
blob:
Content-Security-Policy-Report-Only
No report-only CSP headers found.