Open
Cached
·
just now
3
directives
Content-Security-Policy
Content-Security-Policy: sandbox allow-forms allow-same-origin allow-scripts allow-popups allow-popups-to-escape-sandbox allow-presentation allow-top-navigation-by-user-activation; frame-ancestors 'self' *.huffpost.com *.huffingtonpost.com *.huffpost.net *.buzzfeed.com clients.opinary.com compass.pressekompass.net *.newsbreak.com *.newsbreakapp.com *.upday-content.com *.upday.com *.samsung-news.com; report-uri https://huffpost.report-uri.com/r/d/csp/enforce;
sandbox
Keyword
—
allow-forms
sandbox
Keyword
—
allow-same-origin
sandbox
Keyword
—
allow-scripts
sandbox
Keyword
—
allow-popups
sandbox
Keyword
—
allow-popups-to-escape-sandbox
sandbox
Keyword
—
allow-presentation
sandbox
Keyword
—
allow-top-navigation-by-user-activation
frame-ancestors
Keyword
—
'self'
Content-Security-Policy-Report-Only
No report-only CSP headers found.