Open
Cached
·
just now
4
directives
Content-Security-Policy
Content-Security-Policy: script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.ravelry.com https://*.ravelrycache.com https://*.doorbell.io https://plausible.io https://*.frontapp.com https://apis.google.com https://www.amazon.com https://www.dropbox.com https://*.googleapis.com https://*.google-analytics.com https://www.google.com https://*.gstatic.com https://maps.google.com *.nr-data.net https://*.newrelic.com https://*.twitter.com connect.facebook.net https://*.facebook.com https://*.pinterest.com; object-src 'self' *.ravelry.com *.macromedia.com *.etsy.com *.youtube.com *.vimeo.com *.vimeocdn.com *.gstatic.com; frame-src 'self' https://*.facebook.com https://docs.google.com https://accounts.google.com https://www.amazon.com https://*.spotify.com https://*.buffer.com https://*.vimeo.com https://*.vimeocdn.com https://*.youtube.com https://vine.co https://*.google.com https://*.twitter.com https://*.facebook.com https://*.pinterest.com chromenull://* chromeinvoke://* webviewprogressproxy://*; connect-src 'self' *.ravelry.com https://www2.ravelry.com doorbell.io:443 https://*.nr-data.net https://plausible.io https://*.dropbox.com https://www.ravelry.com wss://websocket.ravelry.com wss://websocket2.ravelry.com *.googleapis.com syndication.twitter.com;
script-src
Keyword
—
'self'
script-src
Keyword
—
'unsafe-inline'
script-src
Keyword
—
'unsafe-eval'
script-src
Host
—
object-src
Keyword
—
'self'
object-src
Host
—
frame-src
Keyword
—
'self'
frame-src
Host
—
chromenull://*
frame-src
Host
—
chromeinvoke://*
frame-src
Host
—
webviewprogressproxy://*
connect-src
Keyword
—
'self'
connect-src
Host
—
Content-Security-Policy-Report-Only
No report-only CSP headers found.