Cached · just now
12 directives

Content-Security-Policy

No enforced CSP headers found.

Content-Security-Policy-Report-Only

default-src Keyword
'self'
script-src Keyword
'self'
script-src Keyword
'report-sample'
script-src Nonce
'nonce-15d8a7b0510652dcdae152916e4079a5df74fb9937d022e01f88d7df1c035e0282cf11535f5f87abcb630a21e3b20e83'
base-uri Keyword
'none'
style-src Keyword
'self'
style-src Keyword
'unsafe-inline'
form-action Keyword
'self'
object-src Keyword
'none'
img-src Keyword
'self'
img-src Scheme
data:
img-src Host
img-src Host
frame-src Keyword
'self'
font-src Keyword
'self'
font-src Scheme
data:
media-src Keyword
'self'
media-src Scheme
blob:
connect-src Keyword
'self'
report-uri Host