Content-Security-Policy-Report-Only | default-src 'self' https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://ajax.aspnetcdn.com https://ajax.googleapis.com https://www.google-analytics.com http://www.google-analytics.com https://translate.googleapis.com https://translate.google.com https://*.charlieschocolatefactory.com http://*.charlieschocolatefactory.com https://*.charlieschocolatefactory.ca http://*.charlieschocolatefactory.ca; style-src 'self' 'unsafe-inline' https://ajax.googleapis.com https://translate.googleapis.com https://fonts.googleapis.com; frame-ancestors 'self'; child-src 'self' gsa://onpageload; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://www.google-analytics.com http://www.google-analytics.com https://translate.googleapis.com; img-src 'self' data: https://ajax.googleapis.com https://www.google-analytics.com http://www.google-analytics.com https://stats.g.doubleclick.net https://translate.googleapis.com https://www.google.com https://www.gstatic.com https://*.charlieschocolatefactory.com http://*.charlieschocolatefactory.com https://*.charlieschocolatefactory.ca http://*.charlieschocolatefactory.ca; reflected-xss block; form-action 'self' https://*.paypal.com; report-uri http://charlieschocolatefactory.com/errors/csp.php |