Open
Cached
·
just now
10
directives
Content-Security-Policy
Content-Security-Policy: default-src https://*.shelf.io https://*.shelf-ssp.com * 'self' https://* https://*.s3.amazonaws.com; script-src https://*.shelf.io https://*.shelf-ssp.com * 'self' 'unsafe-inline' 'unsafe-eval' https://*.amazonaws.com https://*.polyfill.io https://*.google.com https://*.googleapis.com https://*.gstatic.com https://*.getbeamer.com https://*.intercom.io https://*.intercomcdn.com https://*.stripe.com https://*.pendo.io https://*.jsdelivr.net https://*.s3.amazonaws.com https://*.youtube.com https://*.vimeo.com; connect-src https://*.shelf.io https://*.shelf-ssp.com * 'self'; img-src data: https://*.shelf.io https://*.shelf-ssp.com * 'self' blob: chrome-extension://* https://*.s3.amazonaws.com http://* https://*; style-src https://*.shelf.io https://*.shelf-ssp.com * 'self' 'unsafe-inline' https://*.s3.amazonaws.com http://* https://*; object-src https://*.shelf.io https://*.shelf-ssp.com * 'self' https://*.amazonaws.com https://*.google.com https://*.googleapis.com https://*.gstatic.com https://*.intercom.io https://*.intercomcdn.com https://*.stripe.com https://*.pendo.io https://*.getbeamer.com https://*.s3.amazonaws.com; media-src https://*.shelf.io https://*.shelf-ssp.com * 'self' http://* https://*; font-src https://*.shelf.io https://*.shelf-ssp.com * 'self' http://* https://*; frame-src https://*.shelf.io https://*.shelf-ssp.com * 'self' http://* https://*; worker-src https://*.shelf.io https://*.shelf-ssp.com blob:
default-src
Host
—
*
default-src
Keyword
—
'self'
default-src
Host
—
https://*
script-src
Host
—
*
script-src
Keyword
—
'self'
script-src
Keyword
—
'unsafe-inline'
script-src
Keyword
—
'unsafe-eval'
connect-src
Host
—
*
connect-src
Keyword
—
'self'
img-src
Scheme
—
data:
img-src
Host
—
*
img-src
Keyword
—
'self'
img-src
Scheme
—
blob:
img-src
Host
—
chrome-extension://*
img-src
Host
—
http://*
img-src
Host
—
https://*
style-src
Host
—
*
style-src
Keyword
—
'self'
style-src
Keyword
—
'unsafe-inline'
style-src
Host
—
http://*
style-src
Host
—
https://*
object-src
Host
—
*
object-src
Keyword
—
'self'
media-src
Host
—
*
media-src
Keyword
—
'self'
media-src
Host
—
http://*
media-src
Host
—
https://*
font-src
Host
—
*
font-src
Keyword
—
'self'
font-src
Host
—
http://*
font-src
Host
—
https://*
frame-src
Host
—
*
frame-src
Keyword
—
'self'
frame-src
Host
—
http://*
frame-src
Host
—
https://*
worker-src
Scheme
—
blob:
Content-Security-Policy-Report-Only
No report-only CSP headers found.