frame-src 'self' *.project-open.net;img-src 'self';object-src 'none';report-uri /SYSTEM/csp-collector.tcl;script-src显示了一个错误:
Content Security Policy: The page’s settings blocked the loading of a resource at inline (“script-src
我有一个非常简单的CSP头,请注意script-src指令:default-src 'none'; script-src 'self'; script-src-elem 'self' https://,会生成以下冲突:Content Security Policy: The page’s settings blocked the loading of a resource at inline (“script-src