Content-Security-Policy:default-srchttps:;report-uri/csp-violation-report-endpoint/ /csp-violation-report-endpoint
Content-Security-Policy-Report-Only:default-srchttps:;report-uri/csp-violation-report-endpoint/ 如果您仍然希望接收报告
object-src'none' 示例:尚未实施上述政策;而只是报告将会发生的违规行为: Content-Security-Policy-Report-Only:default-srchttps:;report-uri/csp-violation-report-endpoint