Content-Security-Policy | default-src 'self' apis.google.com fonts.gstatic.com fonts.googleapis.com www.google-analytics.com www.youtube.com;script-src 'self' 'unsafe-inline' 'unsafe-eval' apis.google.com fonts.gstatic.com fonts.googleapis.com www.google-analytics.com www.youtube.com;style-src 'self' 'unsafe-inline' fonts.gstatic.com fonts.googleapis.com www.google-analytics.com www.youtube.com;object-src 'self' www.youtube.com https:;media-src 'self' https:;frame-src 'self' accounts.google.com www.youtube.com https:; |