Content-Security-Policy | default-src 'self' https://www.idea.or.id; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.google.com https://www.paypalobjects.com https://www.google-analytics.com https://*.disqus.com https://*.googleapis.com https://*.gstatic.com; img-src 'self' https://www.idea.or.id https://www.paypalobjects.com https://www.google-analytics.com https://*.google.com https://*.googleapis.com https://*.gstatic.com; style-src 'self' 'unsafe-inline' https://*.googleapis.com; font-src 'self' https://themes.googleusercontent.com; frame-src 'self' https://disqus.com; object-src 'none' |