Content-Security-Policy | default-src 'self' http://dfm.de/ https://www.google.com/recaptcha/ https://www.youtube.com/; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://ajax.googleapis.com https://www.google.com/recaptcha/ https://www.gstatic.com https://www.google-analytics.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' http://www.dfm.de/ http://dfm.de/ http://test2.dfm.eu/ http://1.gravatar.com https://www.google-analytics.com https://stats.g.doubleclick.net https://scontent.cdninstagram.com/; font-src 'self' https://fonts.gstatic.com/ |