Content-Security-Policy-Report-Only | child-src 'self' *.facebook.com; connect-src *; default-src 'self'; img-src 'self' about: *.facebook.com https://*.facebook.com unsplash.it https://unsplash.it placehold.it https://placehold.it data: localhost:1337 localhost:1338 blob: api.villada.sfbagency.pilvia.io:81 https://api.villada.sfbagency.pilvia.io:81 api.villada.sfbagency.pilvia.io villadaholidays.com https://villadaholidays.com www.villadaholidays.com https://www.villadaholidays.com api.villadaholidays.com https://api.villadaholidays.com https://api.villada.sfbagency.pilvia.io staging.api.villada.sfbagency.pilvia.io:81 https://staging.api.villada.sfbagency.pilvia.io:81 *.gstatic.com https://*.gstatic.com *.googleapis.com https://*.googleapis.com villada-100.appspot.com https://villada-100.appspot.com lh3.googleusercontent.com https://lh3.googleusercontent.com *.typekit.net https://*.typekit.net scontent.cdninstagram.com https://scontent.cdninstagram.com picsum.photos https://picsum.photos https://www.google-analytics.com google-analytics.com *.doubleclick.net https://*.doubleclick.net *.google.com https://www.google.com https://img.paytrail.com img.paytrail.com *.google.se https://www.google.se *.google.fi https://www.google.fi *.google.dk https://www.google.dk *.google.no https://www.google.no; font-src 'self' fonts.googleapis.com https://fonts.googleapis.com use.fontawesome.com https://use.fontawesome.com fonts.gstatic.com https://fonts.gstatic.com cloud.typography.com https://cloud.typography.com data: use.typekit.net https://use.typekit.net villadaholidays.com https://villadaholidays.com www.villadaholidays.com https://www.villadaholidays.com; object-src 'self'; media-src 'self'; manifest-src 'self'; script-src 'self' 'unsafe-inline' *.facebook.com https://*.facebook.com cdn.polyfill.io https://cdn.polyfill.io use.fontawesome.com https://use.fontawesome.com *.googleapis.com https://*.googleapis.com localhost:1337 localhost:1338 localhost:7331 *.gstatic.com use.typekit.net https://use.typekit.net juicer.io https://juicer.io *.facebook.net https://*.facebook.net villadaholidays.com https://villadaholidays.com www.villadaholidays.com https://www.villadaholidays.com *.googletagmanager.com https://www.googletagmanager.com google-analytics.com https://www.google-analytics.com *.doubleclick.net https://*.doubleclick.net *.google.com https://*.google.com; style-src 'self' 'unsafe-inline' blob: cdn.rawgit.com/milligram/milligram/master/dist/milligram.min.css https://cdn.rawgit.com/milligram/milligram/master/dist/milligram.min.css use.fontawesome.com https://use.fontawesome.com *.googleapis.com https://*.googleapis.com localhost:7331 cloud.typography.com https://cloud.typography.com villadaholidays.com https://villadaholidays.com www.villadaholidays.com https://www.villadaholidays.com *.googletagmanager.com https://www.google-analytics.com google-analytics.com *.doubleclick.net https://*.doubleclick.net; report-uri https://api.villadaholidays.com/api/v1/info/csp-violation-report-endpoint |