Open
Cached
·
just now
14
directives
Content-Security-Policy
Content-Security-Policy: img-src 'self' *.commercecloud.salesforce.com *.powerreviews.com res.cloudinary.com *.maps.googleapis.com maps.gstatic.com *.googletagmanager.com www.google.com www.google.co.in *.google-analytics.com *.adyen.com *.quantummetric.com *.onetrust.com *.cookielaw.org *.evgnet.com *.evergage.com https://cdn.segment.com https://api.segment.io https://cr-eec.etp-proto0.com https://cr-eec.etp-staging.com https://eec.crunchyroll.com/v1 https://eec.crunchyroll.com/v1/t https://*.gstatic.com https://www.paypalobjects.com https://*.crunchyroll.com https://cdn.evergage.com/beacon/etgglobalservices/* *.sezzle.com https://braze-images.com https://ipinfo.io/json https://*.stripe.com https://*.stripecdn.com *.googleads.g.doubleclick.net data:;script-src 'self' *.commercecloud.salesforce.com 'unsafe-eval' 'unsafe-inline' *.powerreviews.com storage.googleapis.com mpsnare.iesnare.com api.cquotient.com *.stripe.com https://js.stripe.com https://*.stripecdn.com vimeo.com *.vimeo.com youtube.com *.youtube.com maps.googleapis.com *.googletagmanager.com googleads.g.doubleclick.net *.google-analytics.com www.google.com *.quantummetric.com *.cookielaw.org *.onetrust.com *.evgnet.com *.evergage.com https://cdn.segment.com https://api.segment.io https://cr-eec.etp-proto0.com https://cr-eec.etp-staging.com https://eec.crunchyroll.com/v1 https://eec.crunchyroll.com/v1/t https://pay.google.com/gp/p/js/pay.js *.marketingcloudapis.com *.auth.marketingcloudapis.com https://www.sandbox.paypal.com https://www.paypal.com https://*.crunchyroll.com https://etgglobalservices.us-7.evergage.com https://etgglobalservices.us-7.evergage.com/* https://cdn.evergage.com/beacon/etgglobalservices/* https://sdk.iad-03.braze.com https://ipinfo.io/json https://runtime.commercecloud.com;connect-src 'self' *.commercecloud.salesforce.com *.powerreviews.com api.cquotient.com *.c360a.salesforce.com *.stripe.com https://*.stripecdn.com vimeo.com *.vimeo.com youtube.com *.youtube.com https://cdn.segment.com https://api.segment.io https://cr-eec.etp-proto0.com https://cr-eec.etp-staging.com https://eec.crunchyroll.com/v1 https://eec.crunchyroll.com/v1/t maps.googleapis.com *.googletagmanager.com *.googleads.g.doubleclick.net *.google-analytics.com www.google.com https://google.com/pagead/ *.adyen.com *.evgnet.com *.evergage.com *.quantummetric.com *.cookielaw.org *.onetrust.com https://www.google.com/pay *.marketingcloudapis.com *.auth.marketingcloudapis.com https://www.sandbox.paypal.com https://www.paypal.com https://*.crunchyroll.com https://etgglobalservices.us-7.evergage.com https://etgglobalservices.us-7.evergage.com/* https://cdn.evergage.com/beacon/etgglobalservices/* *.sezzle.com https://account.demandware.com/dwsso/oauth2/access_token https://sdk.iad-03.braze.com https://ipinfo.io/json https://runtime.commercecloud.com;default-src api.cquotient.com *.commercecloud.salesforce.com *.stripe.com vimeo.com *.vimeo.com youtube.com *.youtube.com *.marketingcloudapis.com *.auth.marketingcloudapis.com *.quantummetric.com *.cookielaw.org *.evgnet.com *.evergage.com *.onetrust.com https://*.crunchyroll.com https://cdn.segment.com https://api.segment.io https://cr-eec.etp-proto0.com https://cr-eec.etp-staging.com https://eec.crunchyroll.com/v1 https://eec.crunchyroll.com/v1/t https://cdn.evergage.com/beacon/etgglobalservices/* https://sdk.iad-03.braze.com https://ipinfo.io/json;frame-src 'self' *.commercecloud.salesforce.com api.cquotient.com *.stripe.com https://*.stripecdn.com https://pay.google.com vimeo.com *.vimeo.com youtube.com *.youtube.com *.adyen.com *.quantummetric.com *.google.com *.googletagmanager.com td.doubleclick.net *.cookielaw.org *.evgnet.com *.evergage.com *.onetrust.com https://www.sandbox.paypal.com https://www.paypal.com https://*.crunchyroll.com https://cdn.segment.com https://api.segment.io https://cr-eec.etp-proto0.com https://cr-eec.etp-staging.com https://eec.crunchyroll.com/v1 https://eec.crunchyroll.com/v1/t https://cdn.evergage.com/beacon/etgglobalservices/* https://sdk.iad-03.braze.com https://ipinfo.io/json;manifest-src 'self' *.commercecloud.salesforce.com *.stripe.com js.stripe.com pay.google.com vimeo.com *.vimeo.com youtube.com *.youtube.com *.googletagmanager.com *.quantummetric.com *.cookielaw.org *.evgnet.com *.evergage.com *.onetrust.com https://www.google.com/pay https://*.crunchyroll.com https://cdn.segment.com https://api.segment.io https://cr-eec.etp-proto0.com https://cr-eec.etp-staging.com https://eec.crunchyroll.com/v1 https://eec.crunchyroll.com/v1/t https://cdn.evergage.com/beacon/etgglobalservices/* https://sdk.iad-03.braze.com https://ipinfo.io/json;upgrade-insecure-requests;base-uri 'self';block-all-mixed-content;font-src 'self' https: data:;frame-ancestors 'self' https://runtime.commercecloud.com;object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
img-src
Keyword
—
'self'
img-src
Host
—
img-src
Scheme
—
data:
script-src
Keyword
—
'self'
script-src
Keyword
—
'unsafe-eval'
script-src
Keyword
—
'unsafe-inline'
script-src
Host
—
script-src
Host
—
script-src
Host
—
connect-src
Keyword
—
'self'
connect-src
Host
—
connect-src
Host
—
connect-src
Host
—
default-src
Host
—
default-src
Host
—
default-src
Host
—
frame-src
Keyword
—
'self'
frame-src
Host
—
manifest-src
Keyword
—
'self'
manifest-src
Host
—
upgrade-insecure-requests
Source
—
(no sources)
base-uri
Keyword
—
'self'
block-all-mixed-content
Source
—
(no sources)
font-src
Keyword
—
'self'
font-src
Scheme
—
https:
font-src
Scheme
—
data:
frame-ancestors
Keyword
—
'self'
object-src
Keyword
—
'none'
script-src-attr
Keyword
—
'none'
style-src
Keyword
—
'self'
style-src
Scheme
—
https:
style-src
Keyword
—
'unsafe-inline'
Content-Security-Policy-Report-Only
No report-only CSP headers found.